What MITRE ATT&CK T1602.001: SNMP (MIB Dump) (Enterprise Tactic TA0009 - Collection) requires
MITRE ATT&CK T1602.001 (SNMP (MIB Dump)) is an Enterprise Collection sub-technique of T1602 (Data from Configuration Repository). Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP). The MIB is a configuration repository that stores variable information accessible via SNMP in the form of object identifiers (OID). Each OID identifies a variable that can be read or set and permits active management tasks, such as configuration changes, through remote modification of these variables. Affected platforms: Network. MITRE-documented mitigations include M1054 Software Configuration, M1051 Update Software, M1041 Encrypt Sensitive Information, M1031 Network Intrusion Prevention, M1030 Network Segmentation, M1037 Filter Network Traffic. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-16, AC-17, AC-18, AC-19, AC-20, CA-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1602/001/
SHA-256 integrity: 0f81d1fc1ab0146860c595cd0e737f6864b798accf19462fba81e564847850bf
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1602.001: SNMP (MIB Dump) (https://attack.mitre.org/techniques/T1602/001/)
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access