Databases - T1213.006 (248d3fe1-7fe1-4d71-91c7-8bb7ef35cad3)
Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments).
Examples of databases from which information may be collected include MySQL, PostgreSQL, MongoDB, Amazon Relational Database Service, Azure SQL Database, Google Firebase, and Snowflake. Databases may include a variety of information of interest to adversaries, such as usernames, hashed passwords, personally identifiable information, and financial data. Data collected from databases may be used for Lateral Movement, Command and Control, or Exfiltration. Data exfiltrated from databases may also be used to extort victims or may be sold for profit.(Citation: Google Cloud Threat Intelligence UNC5537 Snowflake 2024)
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| Databases - T1213.006 (248d3fe1-7fe1-4d71-91c7-8bb7ef35cad3) | Attack Pattern | Data from Information Repositories - T1213 (d28ef391-8ed4-45dc-bc4a-2f43abf54416) | Attack Pattern | 1 |