Tactic.View on attack.mitre.org
The adversary is trying to gather data of interest to their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1005 | Data from Local System | 0 | 230 |
| T1025 | Data from Removable Media | 0 | 24 |
| T1039 | Data from Network Shared Drive | 0 | 13 |
| T1056 | Input Capture | 4 | 200 |
| T1074 | Data Staged | 2 | 159 |
| T1113 | Screen Capture | 0 | 171 |
| T1114 | Email Collection | 3 | 51 |
| T1115 | Clipboard Data | 0 | 46 |
| T1119 | Automated Collection | 0 | 75 |
| T1123 | Audio Capture | 0 | 32 |
| T1125 | Video Capture | 0 | 35 |
| T1185 | Browser Session Hijacking | 0 | 16 |
| T1213 | Data from Information Repositories | 6 | 43 |
| T1530 | Data from Cloud Storage | 0 | 12 |
| T1557 | Adversary-in-the-Middle | 4 | 19 |
| T1560 | Archive Collected Data | 3 | 198 |
| T1602 | Data from Configuration Repository | 2 | 3 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.