Technique.View on attack.mitre.org
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.
This functionality could also be built into remote access tools.
This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.
Rules on DetectionCode tagged with T1119.
| Rule | Level | Log source |
|---|---|---|
| Automated Collection Command PowerShell | medium | windows / ps_script |
| Automated Collection Command Prompt | medium | windows / process_creation |
| Recon Information for Export with Command Prompt | medium | windows / process_creation |
| Recon Information for Export with PowerShell | medium | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| AWS Exfiltration via Anomalous GetObject API Activity | Anomaly | NULL | AWS CloudTrail GetObject |
| AWS Exfiltration via Batch Service | TTP | NULL | AWS CloudTrail JobCreated |
| AWS Exfiltration via DataSync Task | TTP | NULL | AWS CloudTrail CreateTask |
| Windows Dir Piped to Findstr Activity | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows File Collection Via Copy Utilities | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Accessing Windows Recall Directory | Anomaly | NULL | Windows Event Log Security 4663 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius used a custom tool, |
| GroupAPT1 | APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| GroupAPT28 | APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks. |
| GroupChimera | Chimera has used custom DLLs for continuous retrieval of data from memory. |
| GroupConfucius | Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
| GroupEmber Bear | Ember Bear engages in mass collection from compromised systems during intrusions. |
| GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| Used by | Procedure example |
|---|---|
| MalwareAppleSeed | AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration. |
| MalwareAttor | Attor has automatically collected data about the compromised system. |
| MalwareBADNEWS | BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory. |
| MalwareBankshot | Bankshot recursively generates a list of files within a directory and sends them back to the control server. |
| Malwareccf32 | ccf32 can be used to automatically collect files from a compromised host. |
| MalwareComnie | Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server. |
| MalwareCrutch | Crutch can automatically monitor removable drives in a loop and copy interesting files. |
| MalwareDarkGate | DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction. |
| CampaignAPT41 DUST | APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information. |
| CampaignArcaneDoor | ArcaneDoor included collection of packet capture and system configuration information. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used a script to collect information about the infected system. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.