Confluence

T1213.001

Sub-technique of T1213 Data from Information Repositories.View on attack.mitre.org

About this technique

Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as:

* Policies, procedures, and standards
* Physical / logical network diagrams
* System architecture diagrams
* Technical system documentation
* Testing / development credentials (i.e., Unsecured Credentials)
* Work / project schedules
* Source code snippets
* Links to network shares and other internal resources

Detection rules0

Rules on DetectionCode tagged with T1213.001.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupLAPSUS$

LAPSUS$ has searched a victim's network for collaboration platforms like Confluence and JIRA to discover further high-privilege account credentials.

Software1

Used byProcedure example
ToolTruffleHog

TruffleHog has collected credentials and data associated with Confluence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.