// MITRE ATT&CK

T1213.002 · Sharepoint

🎯 Collection Office SuiteWindows Sub-técnica

Sub-técnica de T1213 · Data from Information Repositories.

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example informati...

¿Cómo detectarlo y mitigarlo?

La detección de Sharepoint parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.