Compliance Node Overview
MITRE ATT&CK T1213 (Data from Information Repositories) is an Enterprise Collection technique. Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. ATT&CK documents 5 sub-techniques: T1213.001 Confluence; T1213.002 Sharepoint; T1213.003 Code Repositories; T1213.004 Customer Relationship Management Software; T1213.005 Messaging Applications. Affected platforms: Linux, Windows, macOS, SaaS, IaaS, Office Suite. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1060 Out-of-Band Communications Channel, M1017 User Training, M1054 Software Configuration, M1018 User Account Management, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-21.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1213/
SHA-256 integrity: 42537f7864dfacd92b17365ce127e33849285bb7803615da6411c103bbb58cf7
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1213: Data from Information Repositories (https://attack.mitre.org/techniques/T1213/) with 5 sub-techniques
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access