// MITRE ATT&CK

T1213.006 · Databases

🎯 Collection IaaSLinuxmacOSSaaSWindows Sub-technique

Sub-technique of T1213 · Data from Information Repositories.

Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments). Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazo...

How to detect & mitigate it

Detecting Databases starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.