{"id":"T1119","name":"Automated Collection","url":"https://attack.mitre.org/techniques/T1119","tactics":["collection"],"platforms":["IaaS","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0186","stix_id":"x-mitre-detection-strategy--5e9a51b5-7e4a-4e78-a1ba-215ce937c877","name":"Automated File and API Collection Detection Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0186","analytics":[{"id":"AN0531","stix_id":"x-mitre-analytic--29433de9-360e-4189-9f6d-fb00c9a57e41","name":"Analytic 0531","description":"Automated execution of native utilities and scripts to discover, enumerate, and exfiltrate files and clipboard content. Focus is on detecting repeated file access, scripting engine use, and use of command-line utilities commonly leveraged by collection scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0186#AN0531","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the lookback period for identifying burst activity or patterns in process/file events."},{"field":"SuspiciousFileExtensions","description":"Tunable list of file extensions associated with collection (e.g., .pdf, .docx)."},{"field":"ProcessCountThreshold","description":"The number of times a process executes before considered anomalous."}],"live":true,"detection_strategies":["DET0186"],"techniques":["T1119"]},{"id":"AN0532","stix_id":"x-mitre-analytic--70df3731-9576-4450-bd32-0f52cc8f0ec3","name":"Analytic 0532","description":"Repeated or automated access to user document directories or clipboard using shell scripts or utilities like xclip/pbpaste. Detectable via auditd syscall logs or osquery file events.","url":"https://attack.mitre.org/detectionstrategies/DET0186#AN0532","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"AccessPath","description":"Tunable location for sensitive files like /home/*/Documents."},{"field":"ScriptInterpreterList","description":"Shells or scripting engines to monitor (e.g., bash, python, perl)."}],"live":true,"detection_strategies":["DET0186"],"techniques":["T1119"]},{"id":"AN0533","stix_id":"x-mitre-analytic--f6ad51e5-b869-455d-acb1-ef725acb27cb","name":"Analytic 0533","description":"Use of pbpaste, AppleScript, or third-party automation frameworks (e.g., Automator) to collect clipboard or file content in bursts. Observable via unified logs.","url":"https://attack.mitre.org/detectionstrategies/DET0186#AN0533","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"logMessage contains pbpaste or osascript","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"subsystem=launchservices","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AutomationTool","description":"Detectable script interpreters or clipboard tools (pbpaste, osascript)."},{"field":"ClipboardCheckRate","description":"Threshold for how often clipboard access occurs within a given time window."}],"live":true,"detection_strategies":["DET0186"],"techniques":["T1119"]},{"id":"AN0534","stix_id":"x-mitre-analytic--00b2801f-752e-4b70-95fd-c2644ccef671","name":"Analytic 0534","description":"Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content.","url":"https://attack.mitre.org/detectionstrategies/DET0186#AN0534","platforms":["SaaS"],"log_source_references":[{"name":"azure:signinlogs","channel":"Operation=UserLogin","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"UserAgentFilter","description":"Filter for scripting agents (e.g., Python, PowerShell) which may vary by org."},{"field":"ExpectedClientIPList","description":"Set of known internal or managed IPs to filter benign automation."},{"field":"DeviceProperties","description":"Expected managed device profiles used to detect unmanaged devices."}],"live":true,"detection_strategies":["DET0186"],"techniques":["T1119"]}],"live":true,"version":"1.0","techniques":["T1119"]}],"sigma_rules":[{"id":"0aba5685-6db6-486f-88ef-29a99c545cfd","title":"Shai-Hulud Malicious GitHub Workflow Creation","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-09-24","modified":"2026-01-24","description":"Detects creation of shai-hulud-workflow.yml file associated with Shai Hulud worm targeting NPM supply chain attack that exfiltrates GitHub secrets","references":["https://www.safetycli.com/blog/shai-hulud-npm-attack-runs-malicious-github-action"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.persistence","attack.credential-access","attack.t1552.001","attack.collection","attack.t1119","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Shai-Hulud/file_event_lnx_mal_shai_hulud_workflow.yml","techniques":["T1552.001","T1119"],"cves":[]},{"id":"a9723fcc-881c-424c-8709-fd61442ab3c3","title":"Recon Information for Export with PowerShell","author":"frack113","status":"test","level":"medium","date":"2021-07-30","modified":"2022-12-25","description":"Once established within a system or network, an adversary may use automated techniques for collecting internal data","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1119/T1119.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.collection","attack.t1119"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_recon_export.yml","techniques":["T1119"],"cves":[]},{"id":"aa2efee7-34dd-446e-8a37-40790a66efd7","title":"Recon Information for Export with Command Prompt","author":"frack113","status":"test","level":"medium","date":"2021-07-30","modified":"2022-09-13","description":"Once established within a system or network, an adversary may use automated techniques for collecting internal data.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1119/T1119.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1119"],"path":"rules/windows/process_creation/proc_creation_win_susp_recon.yml","techniques":["T1119"],"cves":[]},{"id":"c1dda054-d638-4c16-afc8-53e007f3fbc5","title":"Automated Collection Command PowerShell","author":"frack113","status":"test","level":"medium","date":"2021-07-28","modified":"2022-12-25","description":"Once established within a system or network, an adversary may use automated techniques for collecting internal data.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1119/T1119.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.collection","attack.t1119"],"path":"rules/windows/powershell/powershell_script/posh_ps_automated_collection.yml","techniques":["T1119"],"cves":[]},{"id":"f576a613-2392-4067-9d1a-9345fb58d8d1","title":"Automated Collection Command Prompt","author":"frack113","status":"test","level":"medium","date":"2021-07-28","modified":"2022-11-11","description":"Once established within a system or network, an adversary may use automated techniques for collecting internal data.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1119/T1119.md","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.001/T1552.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.t1119","attack.credential-access","attack.t1552.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_automated_collection.yml","techniques":["T1119","T1552.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2010-2861","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}