T1213.004sub-technique of T1213 Data from Information Repositories
Customer Relationship Management Software
SaaSnothing on this site yetT1213.004 on attack.mitre.org
Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information. CRM software is used to assist organizations in tracking and managing customer interactions, as well as storing customer data. Once adversaries gain access to a victim organization, they may mine CRM software for customer data.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Suspected data theft by an insider
A resignation with unusual file access, a DLP alert, or an unexplained large transfer.
how MITRE says to see it
Detecting Suspicious Access to CRM Data in SaaS Environments
- Anomalous high-volume access to customer records in CRM software by a non-CRM admin user account, especially following initial authentication from a rare location or device. Behavior includes abnormal access to PII fields or data exports within a short time window.
what reduces it
- M1017 User Training. Develop and publish policies that define acceptable information to be stored in CRM databases and acceptable handling of customer data. Only store customer information required for business operations.
- M1018 User Account Management. Enforce the principle of least-privilege. Consider implementing access control mechanisms that include both authentication and authorization.
- M1054 Software Configuration. Consider implementing data retention policies to automate periodically archiving and/or deleting data that is no longer needed.
- M1047 Audit. Consider periodic review of accounts and privileges for critical and sensitive CRM data.