- Tactics
- Collection
- Platforms
- SaaS
- Reference
- attack.mitre.org/techniques/T1213.001
Description
Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as:
- Policies, procedures, and standards
- Physical / logical network diagrams
- System architecture diagrams
- Technical system documentation
- Testing / development credentials (i.e., Unsecured Credentials)
- Work / project schedules
- Source code snippets
- Links to network shares and other internal resources
How GTK Cyber trains on this
GTK Cyber's Threat Hunting with Data Science course teaches you to build machine-learning detections for techniques like this across the MITRE ATT&CK framework, including the Collection tactic this technique falls under. Practitioner-led, focused on real detections, not memorizing technique IDs.
Related techniques
- T1005 - Data from Local System
- T1025 - Data from Removable Media
- T1039 - Data from Network Shared Drive
- T1056 - Input Capture
- T1074 - Data Staged
- T1113 - Screen Capture
- T1114 - Email Collection
- T1115 - Clipboard Data
- T1119 - Automated Collection
- T1123 - Audio Capture
- T1125 - Video Capture
- T1185 - Browser Session Hijacking