Compliance Node Overview
MITRE ATT&CK T1119 (Automated Collection) is an Enterprise Collection technique. Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data. Affected platforms: Linux, macOS, Windows, IaaS, SaaS, Office Suite. MITRE-documented mitigations include M1029 Remote Data Storage, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-16, AC-17, AC-18, AC-19, AC-20, CM-02, CM-06, CM-08.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1119/
SHA-256 integrity: 50e187cc9933438caafb325e5972b8865d234db42acaeb39874679434d11e093
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1119: Automated Collection (https://attack.mitre.org/techniques/T1119/)
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access