Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org
Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as:
* Policies, procedures, and standards
* Physical / logical network diagrams
* System architecture diagrams
* Technical system documentation
* Testing / development credentials (i.e., Unsecured Credentials)
* Work / project schedules
* Source code snippets
* Links to network shares and other internal resources
Rules on DetectionCode tagged with T1213.001.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupLAPSUS$ | LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials. |
| Used by | Procedure example |
|---|---|
| ToolTruffleHog | TruffleHog has collected credentials and data associated with Confluence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.