Automated Collection Mitigation

Encryption and off-system storage of sensitive information may be one way to mitigate collection of files, but may not stop an adversary from acquiring the information if an intrusion persists over a long period of time and the adversary is able to discover and access the data through other means. A keylogger installed on a system may be able to intercept passwords through <a href="/mitre/techniques/T1056">Input Capture</a> and be used to decrypt protected documents that an adversary may have collected. Strong passwords should be used to prevent offline cracking of encrypted documents through <a href="/mitre/techniques/T1110">Brute Force</a> techniques. Identify unnecessary system utilities, third-party tools, or potentially malicious software that may be used to collect files and audit and/or block them by using whitelisting (Citation: Beechey 2010) tools, like AppLocker, (Citation: Windows Commands JPCERT) (Citation: NSA MS AppLocker) or Software Restriction Policies (Citation: Corio 2008) where appropriate. (Citation: TechNet Applocker vs SRP)
ID: T1119
Version: 1.0
Created: 17 Oct 2018
Last Modified: 23 Aug 2021

Techniques Addressed by Mitigation

Domain ID Name Use
Enterprise T1119 Automated Collection

