Data from Information Repositories T1213
Tactic: Collection
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4662 | An operation was performed on an object. |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 55 rules share fields, values, and exclusions.
Fields filtered most (69 distinct)
These fields appear most often in rule filters.
Top indicator values (266 distinct)
These values appear most often in rule predicates.
Exclusions (38 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 12 rules
- Bitbucket Full Data Export Triggered
- Bitbucket Unauthorized Full Data Export Triggered
- Bitbucket User Details Export Attempt Detected
- Bitbucket User Permissions Export Attempt
- Github Delete Action Invoked
- Github Outside Collaborator Detected
- Github Self Hosted Runner Changes Detected
- OpenCanary - GIT Clone Request
- OpenCanary - MSSQL Login Attempt Via SQLAuth
- OpenCanary - MSSQL Login Attempt Via Windows Authentication
- OpenCanary - MySQL Login Attempt
- OpenCanary - REDIS Action Command Attempt
Elastic 20 rules
- Access to a Sensitive LDAP Attribute
- AWS DynamoDB Scan by Unusual User
- AWS DynamoDB Table Exported to S3
- AWS RDS Snapshot Export
- AWS Secrets Manager Rapid Secrets Retrieval
- Azure Key Vault Excessive Secret or Key Retrieved
- Entra ID Sharepoint or OneDrive Accessed by Unusual Client
- First Occurrence of GitHub Repo Interaction From a New IP
- First Occurrence of GitHub User Interaction with Private Repo
- First Time Seen NFS AUTH_SYS Root UID Access
- Github Activity on a Private Repository from an Unusual IP
- GitHub Exfiltration via High Number of Repository Clones by User
- High Number of Cloned GitHub Repos From PAT
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- M365 SharePoint Search for Sensitive Content
- M365 SharePoint/OneDrive File Access via PowerShell
- Potential Database Dumping Activity
- Potential Secret Scanning via Gitleaks
- Potential Veeam Credential Access Command
- PowerShell Script with Veeam Credential Access Capabilities
Splunk 1 rule
Kusto 9 rules
- GitLab - Personal Access Tokens creation over time
- Jira - Workflow scheme copied
- Pathlock TDnR - HR User Master Change Requests
- Pathlock TDnR - OData Application Log Events
- Pathlock TDnR - SAP Read Access Logging Audit
- Pathlock TDnR - SAP Read Access Logging Data
- Pathlock TDnR - Spool Job Changes
- Response rows stateful anomaly on database
- Users searching for VIP user activity
YARA-L 3 rules
- GitHub Access Granted To Personal Access Token Followed By High Number Of Cloned Non Public Repositories
- GitHub High Number Of Non Public GitHub Repositories Cloned
- GitHub High Number Of Non Public GitHub Repositories Downloaded
Panther 10 rules
- AppOmni Alert Passthrough
- Databricks TruffleHog Scan Detected
- External GSuite File Share
- GSuite Document External Ownership Transfer
- GSuite External Drive Document
- GSuite Overly Visible Drive Document
- Okta SWA Bulk Access, New Source, and Credential Extraction - Behavioral
- Snowflake Data Exfiltration
- Snowflake Data Exfiltration
- Zendesk Credit Card Redaction Off