Automated Collection

T1119

Technique.View on attack.mitre.org

About this technique

Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.

In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.

This functionality could also be built into remote access tools.

This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.

Detection rules10

Rules on DetectionCode tagged with T1119.

Sigma4

RuleLevelLog source
Automated Collection Command PowerShellmediumwindows / ps_script
Automated Collection Command Promptmediumwindows / process_creation
Recon Information for Export with Command Promptmediumwindows / process_creation
Recon Information for Export with PowerShellmediumwindows / ps_script

Splunk6

RuleTypeRiskData source
AWS Exfiltration via Anomalous GetObject API ActivityAnomalyNULLAWS CloudTrail GetObject
AWS Exfiltration via Batch ServiceTTPNULLAWS CloudTrail JobCreated
AWS Exfiltration via DataSync TaskTTPNULLAWS CloudTrail CreateTask
Windows Dir Piped to Findstr ActivityHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows File Collection Via Copy UtilitiesAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Process Accessing Windows Recall DirectoryAnomalyNULLWindows Event Log Security 4663

Groups21

Software48

Show 24 more

Campaigns6

Procedure examples75

Groups21

Used byProcedure example
GroupAgrius

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information.

GroupAPT1

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

GroupAPT28

APT28 used a publicly available tool to gather and compress multiple documents on the DCCC and DNC networks.

GroupChimera

Chimera has used custom DLLs for continuous retrieval of data from memory.

GroupConfucius

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

GroupEmber Bear

Ember Bear engages in mass collection from compromised systems during intrusions.

GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

View all 21 groups examples

Software48

Used byProcedure example
MalwareAppleSeed

AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration.

MalwareAttor

Attor has automatically collected data about the compromised system.

MalwareBADNEWS

BADNEWS monitors USB devices and copies files with certain extensions to a predefined directory.

MalwareBankshot

Bankshot recursively generates a list of files within a directory and sends them back to the control server.

Malwareccf32

ccf32 can be used to automatically collect files from a compromised host.

MalwareComnie

Comnie executes a batch script to store discovery information in %TEMP%\info.dat and then uploads the temporarily file to the remote C2 server.

MalwareCrutch

Crutch can automatically monitor removable drives in a loop and copy interesting files.

MalwareDarkGate

DarkGate searches for stored credentials associated with cryptocurrency wallets and notifies the command and control server when identified.

View all 48 software examples

Campaigns6

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to automatically collect and process large volumes of data from without human direction.

CampaignAPT41 DUST

APT41 DUST used tools such as SQLULDR2 and PINEGROVE to gather local system and database information.

CampaignArcaneDoor

ArcaneDoor included collection of packet capture and system configuration information.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to automatically gather the username, domain name, machine name, and other system information.

CampaignOperation Wocao

During Operation Wocao, threat actors used a script to collect information about the infected system.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used a command shell to automatically iterate through web.config files to expose and collect machineKey settings.

References1

  1. Mandiant UNC3944 SMS Phishing 2023 Open source
    Mandiant Intelligence. (2023, September 14). Why Are You Texting Me? UNC3944 Leverages SMS Phishing Campaigns for SIM Swapping, Ransomware, Extortion, and Notoriety. Retrieved January 2, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.