| name | T1213.006_databases |
| description | Adversaries may leverage databases to mine valuable information. |
| category | information-gathering |
| version | 18.1 |
| author | cyberstrike-official |
| tags | ["mitre-attack","enterprise","t1213.006","collection","linux","windows","macos","iaas","saas","sub-technique"] |
| technique_id | T1213.006 |
| tactic | collection |
| all_tactics | ["collection"] |
| platforms | ["Linux","Windows","macOS","IaaS","SaaS"] |
| mitre_url | https://attack.mitre.org/techniques/T1213/006 |
| tech_stack | ["linux","windows","macos","cloud","saas"] |
| cwe_ids | ["CWE-200"] |
| chains_with | ["T1213","T1213.001","T1213.002","T1213.003","T1213.004","T1213.005"] |
| prerequisites | ["T1213"] |
| severity_boost | {"T1213":"Chain with T1213 for deeper attack path","T1213.001":"Chain with T1213.001 for deeper attack path","T1213.002":"Chain with T1213.002 for deeper attack path"} |
T1213.006 Databases
Sub-technique of: T1213
High-Level Description
Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit.
Kill Chain Phase
Platforms: Linux, Windows, macOS, IaaS, SaaS
What to Check
How to Test
Manual Testing
-
Identify Attack Surface: Determine if the target environment is susceptible to Databases by examining the target platforms (Linux, Windows, macOS).
-
Assess Existing Defenses: Review whether mitigations for T1213.006 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
-
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Remediation Guide
M1017 User Training
Develop and publish policies that define acceptable information to be stored in databases and acceptable handling of customer data. Only store information required for business operations.