MITRE ATT&CK technique
Automated Collection detection rulesT1119
Automated Collection (T1119) is a MITRE ATT&CK technique in the Collection tactic. This page lists the 5 community-maintained Sigma detection rules in the library mapped to T1119 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux.
Tactic
Shai-Hulud Malicious GitHub Workflow Creation
highDetects creation of shai-hulud-workflow.yml file associated with Shai Hulud worm targeting NPM supply chain attack that exfiltrates GitHub secrets
linux · file_event
Automated Collection Command PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · ps_script
Automated Collection Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
Recon Information for Export with Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
Recon Information for Export with PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data
windows · ps_script