T1119 Automated Collection
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Shai-Hulud Malicious GitHub Workflow Creationhighexperimental · linux
- Automated Collection Command PowerShellmediumtest · windows
- Automated Collection Command Promptmediumtest · windows
- Recon Information for Export with Command Promptmediumtest · windows
- Recon Information for Export with PowerShellmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.