Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1213

T1213Data from Information Repositories

T1213 — Data from Information Repositories is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 14 detection use cases covering it and 11 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
14Use cases
11Articles
6Sub-techniques
1Tactic

Sub-techniques (6)

Use cases covering this technique (14)

[WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD [LLM] NodeBB ActivityPub private-message disclosure via unsigned GET enumeration Bespoke actions · alerting SP [LLM] Unauthenticated NodeBB ActivityPub category-outbox private-content disclosure Bespoke actions · hunting SΣP [LLM] Rapid multi-artifact enumeration on Gitea V4 DownloadArtifact endpoint (CVE-2026-58426 cross-task scan) Bespoke actions · hunting SP [LLM] LightRAG CVE-2026-61736: cross-origin credentialed read of /documents or /query (data exfil) Bespoke actions · hunting SP [LLM] MantisBT SOAP endpoint (mantisconnect.php) high-volume POST burst — mass data exfiltration Bespoke actions · alerting SP [LLM] n8n-MCP cross-tenant workflow version read/enumeration via n8n_workflow_versions (CVE-2026-54052) Bespoke recon · hunting SP [LLM] Bulk enumeration of 9router /api/usage/request-details (conversation-history exfiltration) Bespoke actions · hunting SP [LLM] Rocket.Chat Livechat file-upload ID enumeration sweep (ObjectId harvest) Bespoke actions · alerting SP [LLM] Rocket.Chat anonymous Livechat visitor bootstrap chained to file-upload access Bespoke exploit · alerting SP [LLM] CVE-2026-50027 unauthenticated bulk read/enumeration of mcp-memory-service document store Bespoke actions · alerting SP [LLM] Klue/Icarus: bulk Salesforce CRM record retrieval via connected app (Case/Contact/Account/Opportunity) Bespoke actions · alerting DSP [LLM] Hoppscotch cross-team request injection via moveRequest GraphQL with null nextRequestID Bespoke exploit · hunting SPDD [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (11)