kevmap

TechniquesT1213 › AN1160

AN1160 Analytic 1160

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.</p>
Detects
T1213 Data from Information Repositories
Part of
DET0413 Abuse of Information Repositories for Data Collection

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=5145DC0102 Network Share Access
m365:unifiedAccessed SharePoint files or pagesDC0025 Cloud Storage Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
UserContextPrivileged users may be excluded if they routinely perform admin actions on SharePoint or file shares.
AccessVolumeThresholdThe number of files accessed or pages retrieved in a short window to flag as abnormal.
TimeWindowThe time range (e.g., 5 minutes, 1 hour) in which burst access patterns are considered anomalous.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-24086Adobe Commerce and Magento Open SourceMapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM)Mapped