T1213.001SubTechniquecollectionagent-callable

T1213.001Confluence

Sub-technique of T1213

Platforms: SaaS

ATT&CK version: 14.1

What it is

Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA, Confluence is generally used to store development-related documentation, however, in general may contain more diverse categories of useful information, such as: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials * Work / project schedules * Source code snippets * Links to network shares and other internal resources

ATT&CK tactics· 1

Collection

References

  1. https://attack.mitre.org/techniques/T1213/001
  2. https://confluence.atlassian.com/confkb/how-to-enable-user-access-logging-182943.html
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.