T1213.002sub-technique of T1213 Data from Information Repositories
Sharepoint
Office Suite · Windowsnothing on this site yetT1213.002 on attack.mitre.org
Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Suspected data theft by an insider
A resignation with unusual file access, a DLP alert, or an unexplained large transfer.
how MITRE says to see it
Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
- Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents.
what reduces it
- M1017 User Training. Develop and publish policies that define acceptable information to be stored in SharePoint repositories.
- M1018 User Account Management. Enforce the principle of least-privilege. Consider implementing access control mechanisms that include both authentication and authorization.
- M1047 Audit. Consider periodic review of accounts and privileges for critical and sensitive SharePoint repositories.