Sharepoint

T1213.002

Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org

About this technique

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

* Policies, procedures, and standards
* Physical / logical network diagrams
* System architecture diagrams
* Technical system documentation
* Testing / development credentials (i.e., Unsecured Credentials)
* Work / project schedules
* Source code snippets
* Links to network shares and other internal resources

Detection rules1

Rules on DetectionCode tagged with T1213.002.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
O365 SharePoint Suspicious Search BehaviorAnomalyNULLOffice 365 Universal Audit Log

Groups7

Software2

Campaigns1

Procedure examples10

Groups7

Used byProcedure example
GroupAkira

Akira has accessed and downloaded information stored in SharePoint instances as part of data gathering and exfiltration activity.

GroupAPT28

APT28 has collected information from Microsoft SharePoint services within target networks.

GroupChimera

Chimera has collected documents from the victim's SharePoint.

GroupHAFNIUM

HAFNIUM has abused compromised credentials to exfiltrate data from SharePoint.

GroupKe3chang

Ke3chang used a SharePoint enumeration and data dumping tool known as spwebmember.

GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like SharePoint to discover further high-privilege account credentials.

GroupVOID MANTICORE

VOID MANTICORE has accessed victim’s public facing SharePoint servers and exfiltrated data.

Software2

Used byProcedure example
Toolspwebmember

spwebmember is used to enumerate and dump information from Microsoft SharePoint.

ToolTruffleHog

TruffleHog has searched SharePoint for data and credentials.

Campaigns1

Used byProcedure example
CampaignC0027

During C0027, Scattered Spider accessed victim SharePoint environments to search for VPN and MFA enrollment information, help desk instructions, and new hire guides.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.