Automated Collection T1119

Tactic: Collection

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.

Events covered

25 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 41 rules share fields, values, and exclusions.

Fields filtered most (69 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name11in 4, eq 3, regex_match 3, contains 1(?i)ipconfig.exe, (?i)net1?.exe, (?i)nltest.exe, find, (?i)\w+\.(exe)
CommandLine9contains 4, regex_match 4, eq 2, in 1(?i)\w+\.(bat|ps1|sh), /b , /e , /s , *.7z*
EventType8eq 5, in 2, wildcard 1exec, ProcessRollup2, createinstanceexporttask, createstoreimagetask, exec_event
DeviceEventClassID6ne 4, eq 2asc, audit, campaigns, hsc
DeviceProduct6eq 6X Series
DeviceVendor6eq 6Vectra Networks
EventID6eq 61, 4688, 4662, 4663
event.type6eq 6start
ActionType3eq 2, in 1, ne 1ConnectionSuccess, ListeningConnectionCreated, createremotethreadapicall, memoryremoteprotect
OriginalFileName3eq 2, in 1copy.exe, doskey.exe, findstr.exe, sc.exe, wmic.exe
aws::eventName3eq 3createtask, getobject, jobcreated
parent_process_name3eq 1, is_not_null 1, regex_match 1(?i)\w+\.(exe), osascript
process.args3eq 3, starts_with 1, wildcard 1-type, f, -p, /Users/*/Library/Application Support/*, /private/tmp/
sourcetype3eq 3aws:cloudtrail
triaged3ne 3True

Top indicator values (348 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
DeviceProducteq
X Series
67
DeviceVendoreq
Vectra Networks
67
event.typeeq
start
61078
EventTypeeq
exec
5576
DeviceEventClassIDne
asc
44
DeviceEventClassIDne
audit
44
DeviceEventClassIDne
campaigns
44
DeviceEventClassIDne
health
44
DeviceEventClassIDne
hsc
44
CommandLineregex_match
(?i)\w+\.(bat|ps1|sh)
33
sourcetypeeq
aws:cloudtrail
359
triagedne
True
33
ActionTypeeq
ConnectionSuccess
211
Categoryin
BOTNET ACTIVITY
22
Categoryin
COMMAND & CONTROL
22
Categoryin
EXFILTRATION
22
Categoryin
LATERAL MOVEMENT
22
Categoryin
RECONNAISSANCE
22
DestinationPorteq
9389
25
EventIDeq
1
2241
EventIDeq
4688
2317
QueryExecutionStatuseq
success
24
QueryTypeeq
select
22
event.outcomeeq
success
2369
levelin
Critical
22
levelin
High
22
process.argseq
-type
22
process.argseq
f
22
process_nameeq
find
210
process_nameregex_match
(?i)ipconfig.exe
22

Exclusions (63 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinestarts_with
event0.process.command_line
2
CommandLinestarts_with
event1.process.command_line
2
CommandLinestarts_with
find /var/tmp/portage/
1
Accountends_with
$
1
AdditionalExtensionscontains
account
1
AlertNamecontains
0108
1
CommandLineends_with
/tmp/NBInstallAnswer.conf
1
CommandLinein
find /etc/zerum-stacks/lynx/wdr_proxy/.htpasswd -type f
1
CommandLinein
find /run/credentials/getty@tty3.service -xdev -type f ( -perm -0002 -a !...
1
CommandLinein
find /run/credentials/getty@tty4.service -xdev -type f ( -perm -0002 -a !...
1
CommandLinein
find /run/snapd/ns/authd-msentraid.mnt -xdev -type f -perm -002 -exec chmod o-w {} ;
1
CurrentDirectoryeq
/tmp/plz_sandbox
1
CurrentDirectorywildcard
/__w/Modular-Teepee/Modular-Teepee
1
CurrentDirectorywildcard
/build*
1
CurrentDirectorywildcard
/opt/netconfs/home/*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 5 rules

Elastic 8 rules

Splunk 12 rules

Kusto 16 rules