Compliance Node Overview
MITRE ATT&CK T1213.001 (Confluence) is an Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials (i.e., Unsecured Credentials) * Work. Affected platforms: SaaS. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-21.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1213/001/
SHA-256 integrity: ac0c05967f55b5b9f7811151dfa8426e47a7f83e21e6ed8de4d86175b34caef2
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1213.001: Confluence (https://attack.mitre.org/techniques/T1213/001/)
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access