T1039Techniquecollectionagent-callable

T1039Data from Network Shared Drive

Platforms: Linux · macOS · Windows

ATT&CK version: 14.1

What it is

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within [cmd](https://attack.mitre.org/software/S0106) may be used to gather information.

ATT&CK tactics· 1

Collection

References

  1. https://attack.mitre.org/techniques/T1039
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1039: Data from Network Shared Drive | SQUR Knowledge Base