T1213.005sub-technique of T1213 Data from Information Repositories
Messaging Applications
Office Suite · SaaSnothing on this site yetT1213.005 on attack.mitre.org
Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications: * Testing / development credentials (i.e., Chat Messages) * Source code snippets * Links to network shares and other internal resources * Proprietary data * Discussions about...
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Suspected data theft by an insider
A resignation with unusual file access, a DLP alert, or an unexplained large transfer.
how MITRE says to see it
Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
- Atypical access to Slack or Teams conversations via APIs, automation tokens, or bulk message export functionality, particularly after an account takeover or rare sign-in pattern. Often includes mass retrieval of chat history, download of message content, or scraping of workspace/channel metadata.
- Suspicious access to Microsoft Teams chat messages via eDiscovery, Graph API, or export methods after rare or compromised sign-in. Often associated with excessive file access, sensitive content review, or anomaly from expected user behavior.
what reduces it
- M1017 User Training. Develop and publish policies that define acceptable information to be posted in chat applications.
- M1060 Out-of-Band Communications Channel. Implement secure out-of-band communication channels to use as an alternative to in-network chat applications during a security incident. This ensures that critical communications remain secure even if primary messaging channels are compromised by adversaries.
- M1047 Audit. Preemptively search through communication services to find inappropriately shared data, and take actions to reduce exposure when found.