1200KM / detection
T1213 Data from Information Repositories — Detection Rules
Detection workspace for T1213 Data from Information Repositories: 7 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Bitbucket User Details Export Attempt Detected · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- Bitbucket User Permissions Export Attempt · test · medium · {"product":"bitbucket","service":"audit","definition":"Requirements: \"Advance\" log level is required to receive these audit events."}
- OpenCanary - GIT Clone Request · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - MSSQL Login Attempt Via SQLAuth · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - MSSQL Login Attempt Via Windows Authentication · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - MySQL Login Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - REDIS Action Command Attempt · test · high · {"category":"application","product":"opencanary"}
Atlas deterministic concepts
T1213 Data from Information Repositories
COUNT(repository_reads_or_exports BY actor, 10m) >= threshold OR MATCH(bulk_export_operation) -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0413 Abuse of Information Repositories for Data Collection
AN1160 Analytic 1160
Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.
AN1161 Analytic 1161
Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives.
AN1162 Analytic 1162
Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs.
AN1163 Analytic 1163
Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Cloud Service Modification · DC0069
- Cloud Storage Access · DC0025
- Command Execution · DC0064
- File Access · DC0055
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.