TA0009ATT&CK 14.1

TA0009Collection

Description

The adversary is trying to gather data of interest to their goal. Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.

Techniques in this tactic· 17

T1005
Data from Local System
T1025
Data from Removable Media
T1039
Data from Network Shared Drive
T1056
Input Capture
T1074
Data Staged
T1113
Screen Capture
T1114
Email Collection
T1115
Clipboard Data
T1119
Automated Collection
T1123
Audio Capture
T1125
Video Capture
T1185
Browser Session Hijacking
T1213
Data from Information Repositories
T1530
Data from Cloud Storage
T1557
Adversary-in-the-Middle
T1560
Archive Collected Data
T1602
Data from Configuration Repository

Sub-techniques in this tactic· 20

T1056.001T1056.002T1056.003T1056.004T1074.001T1074.002T1114.001T1114.002T1114.003T1213.001T1213.002T1213.003T1557.001T1557.002T1557.003T1560.001T1560.002T1560.003T1602.001T1602.002

References

  1. https://attack.mitre.org/tactics/TA0009

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Tactic
Exfiltration
Tactic
Reconnaissance
Technique
Email Collection
Tactic
Discovery
Tactic
Credential Access
Technique
Input Capture
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, Founder at SQUR.