1200KM / simulation
T1119 Automated Collection — Attack Simulation
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or…
Technique description
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals. In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Automated Collection PowerShell
Procedure 634bd9b9-dc83-4229-b19f-7f83ba9ad313; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Recon information for export with Command Prompt
Procedure aa1180e2-f329-4e1e-8625-2472ec0bfaf3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Recon information for export with PowerShell
Procedure c3f6d794-50dd-482f-b640-0384fbb7db26; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Automated Collection Command Prompt
Procedure cb379146-53f1-43e0-b884-7ce2c635ff5b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Threat Group-3390 · G0027
- FIN6 · G0037
- Patchwork · G0040
- menuPass · G0045
- Gamaredon Group · G0047
- OilRig · G0049
- FIN5 · G0053
- Tropic Trooper · G0081
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Mustang Panda · G0129
- Confucius · G0142
- Ember Bear · G1003
- Agrius · G1030
- Winter Vivern · G1035
- RedCurl · G1039
- VOID MANTICORE · G1055
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.