ATT&CKMatrixCollection

Collection

TA0009

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to gather data of interest to their goal.

Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.

Techniques17

IDNameSub-techniquesExamples
T1005Data from Local System0230
T1025Data from Removable Media024
T1039Data from Network Shared Drive013
T1056Input Capture4200
T1074Data Staged2159
T1113Screen Capture0171
T1114Email Collection351
T1115Clipboard Data046
T1119Automated Collection075
T1123Audio Capture032
T1125Video Capture035
T1185Browser Session Hijacking016
T1213Data from Information Repositories643
T1530Data from Cloud Storage012
T1557Adversary-in-the-Middle419
T1560Archive Collected Data3198
T1602Data from Configuration Repository23

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.