Data from Information Repositories T1213
Tactic: Collection
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4662 | An operation was performed on an object. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
Patterns shared across the 54 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (66 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (263 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (39 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 12 rules
- Bitbucket Full Data Export Triggered
- Bitbucket Unauthorized Full Data Export Triggered
- Bitbucket User Details Export Attempt Detected
- Bitbucket User Permissions Export Attempt
- Github Delete Action Invoked
- Github Outside Collaborator Detected
- Github Self Hosted Runner Changes Detected
- OpenCanary - GIT Clone Request
- OpenCanary - MSSQL Login Attempt Via SQLAuth
- OpenCanary - MSSQL Login Attempt Via Windows Authentication
- OpenCanary - MySQL Login Attempt
- OpenCanary - REDIS Action Command Attempt
Elastic 19 rules
- Access to a Sensitive LDAP Attribute
- AWS DynamoDB Scan by Unusual User
- AWS DynamoDB Table Exported to S3
- AWS RDS Snapshot Export
- AWS Secrets Manager Rapid Secrets Retrieval
- Azure Key Vault Excessive Secret or Key Retrieved
- Entra ID Sharepoint or OneDrive Accessed by Unusual Client
- First Occurrence of GitHub Repo Interaction From a New IP
- First Occurrence of GitHub User Interaction with Private Repo
- Github Activity on a Private Repository from an Unusual IP
- GitHub Exfiltration via High Number of Repository Clones by User
- High Number of Cloned GitHub Repos From PAT
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- M365 SharePoint Search for Sensitive Content
- M365 SharePoint/OneDrive File Access via PowerShell
- Potential Database Dumping Activity
- Potential Secret Scanning via Gitleaks
- Potential Veeam Credential Access Command
- PowerShell Script with Veeam Credential Access Capabilities
Splunk 1 rule
Kusto 9 rules
- GitLab - Personal Access Tokens creation over time
- Jira - Workflow scheme copied
- Pathlock TDnR - HR User Master Change Requests
- Pathlock TDnR - OData Application Log Events
- Pathlock TDnR - SAP Read Access Logging Audit
- Pathlock TDnR - SAP Read Access Logging Data
- Pathlock TDnR - Spool Job Changes
- Response rows stateful anomaly on database
- Users searching for VIP user activity
YARA-L 3 rules
- GitHub Access Granted To Personal Access Token Followed By High Number Of Cloned Non Public Repositories
- GitHub High Number Of Non Public GitHub Repositories Cloned
- GitHub High Number Of Non Public GitHub Repositories Downloaded
Panther 10 rules
- AppOmni Alert Passthrough
- Databricks TruffleHog Scan Detected
- External GSuite File Share
- GSuite Document External Ownership Transfer
- GSuite External Drive Document
- GSuite Overly Visible Drive Document
- Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral
- Snowflake Data Exfiltration
- Snowflake Data Exfiltration
- Zendesk Credit Card Redaction Off