kevmap

TechniquesT1213 › T1213.002

T1213.002 Sharepoint

collection — Office Suite, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1213.002
0
KEV CVEs mapped here
<p>Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:</p>
    <li>Policies, procedures, and standards</li><li>Physical / logical network diagrams</li><li>System architecture diagrams</li><li>Technical system documentation</li><li>Testing / development credentials (i.e., Unsecured Credentials)</li><li>Work / project schedules</li><li>Source code snippets</li><li>Links to network shares and other internal resources</li>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1213.002

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1213) 7

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 3ec9a16d-0b4f-4967-9542-ebf38ceac7dd
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
Techniques: T1003T1213
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 4fe17521-aef3-4e6a-9d6b-4a7c8de155a8
Detects instances where a GIT service on an OpenCanary node has had Git Clone request.
Techniques: T1213
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 5259cbf2-0a75-48bf-b57a-c54d6fabaef3
Detects user data export activity.
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 547dfc53-ebf6-4afe-8d2e-793d9574975d
Detects instances where a REDIS service on an OpenCanary node has had an action command attempted.
Techniques: T1003T1213
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 6e78f90f-0043-4a01-ac41-f97681613a66
Detects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
Techniques: T1003T1213
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 87cc6698-3e07-4ba2-9b43-a85a73e151e2
Detects user permission data export attempt.
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · e7d79a1b-25ed-4956-bd56-bd344fa8fd06
Detects instances where a MySQL service on an OpenCanary node has had a login attempt.
Techniques: T1003T1213