Skip to content
Every technique
T0893Not expressible in SigmaICS

Data from Local System

CollectionNone

Where this stands

No Sigma rule can address this — the telemetry MITRE names has no Sigma logsource behind it.

Sigma has no logsource taxonomy for ICS. MITRE's telemetry here is operational historians and controller state, which no Sigma rule can address.

What the technique is

Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases. This can include sensitive data such as specifications, schematics, or diagrams of control system layouts, devices, and processes. Adversaries may do this using Command-Line Interface or Scripting techniques to interact with the file system to gather information. Adversaries may also use Automated Collection on the local system.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1881

    Monitor for unexpected/abnormal access to files that may be malicious collection of local data, such as user files (e.g.,.pdf,.docx,.jpg,.dwg) or local databases. Monitor for newly executed processes that may search local system sources, such as file systems or local databases, to find files of interest and sensitive data. Monitor for any suspicious attempts to enable scripts running on a system. If scripts are not commonly used on a system, but enabled, scripts running out of cycle from patching or other administrator functions are suspicious. Scripts should be captured from the file system when possible to determine their actions and intent. […]

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.