T1213.002sub-technique of T1213 Data from Information Repositories

Sharepoint

Office Suite · Windowsnothing on this site yetT1213.002 on attack.mitre.org

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

how MITRE says to see it

Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users

  • Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents.

what reduces it

  • M1017 User Training. Develop and publish policies that define acceptable information to be stored in SharePoint repositories.
  • M1018 User Account Management. Enforce the principle of least-privilege. Consider implementing access control mechanisms that include both authentication and authorization.
  • M1047 Audit. Consider periodic review of accounts and privileges for critical and sensitive SharePoint repositories.

the rest of T1213

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.