T1119: Automated Collection
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.CitationMandiant UNC3944 SMS Phishing 2023
This functionality could also be built into remote access tools.
This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.
Security context for executives and security teams
Automated Collection matters because it turns a foothold into repeatable, scalable internal data gathering across endpoints, cloud, SaaS, Office suites, and infrastructure environments. For leaders, the key issue is not just whether an attacker can access one file, but whether they can quietly script or automate collection of many sensitive files, objects, or datasets before defenders notice.
Executive priority
Prioritize this technique where sensitive business data, regulated records, security logs, or cloud-hosted datasets are broadly accessible. Executives should ask whether the organization can prove who accessed, searched, copied, or staged sensitive data across Windows, Linux, macOS, IaaS, SaaS, and Office Suite environments. ATT&CK relationships also show this behavior is used by multiple campaigns and groups, making it a common enough collection pattern to justify control validation, audit evidence review, and incident response playbooks.
Technical view
SOC and IR teams should validate visibility into scripted file searches, bulk copy activity, recurring collection jobs, remote access tool behavior that gathers files, and cloud/API-driven data collection. The technique explicitly connects to command and scripting interpreters, file and directory discovery, lateral tool transfer, cloud service dashboards, and cloud storage object discovery, so detection should correlate discovery, enumeration, copying, and unusual API or ETL activity rather than relying on a single event. The supplied relationship to DET0186 indicates a relevant detection strategy: Automated File and API Collection Detection Across Platforms.
Likely telemetry
- Endpoint process creation and command-line telemetry for scripting interpreters and file-copy utilities
- File system audit events showing searches, reads, copies, archive/staging behavior, or repeated access by file type, path, or name
- Scheduled or recurring execution evidence when collection occurs at intervals
- Remote access tool activity where available from endpoint or management logs
- Cloud control-plane and API audit logs for object listing, object reads, exports, data pipeline activity, CLI use, and ETL service activity
Detection direction
- Validate coverage across all supported platforms listed by ATT&CK: IaaS, Linux, macOS, Office Suite, SaaS, and Windows.
- Tune analytics for sequences: discovery or enumeration followed by bulk reads, copies, exports, or staging activity.
- Baseline legitimate administrative, backup, indexing, eDiscovery, ETL, and data pipeline behavior to reduce false positives.
- Look for automation indicators such as repeated access patterns, scripted command lines, service-account-driven collection, or unusual time intervals.
- Correlate endpoint and cloud/SaaS evidence; endpoint-only monitoring can miss API-based collection, while cloud-only monitoring can miss local scripted file collection.
Mitigation priorities
- Identify and reduce unnecessary access to sensitive repositories so automated collection yields less data if an account or host is compromised.
- Apply M1041 Encrypt Sensitive Information for data at rest, in transit, and during processing where appropriate, especially for sensitive files and datasets.
- Apply M1029 Remote Data Storage for critical logs and sensitive evidence so responders retain forensic visibility even if endpoints are accessed or tampered with.
- Review cloud API, CLI, ETL, and data pipeline permissions to limit unnecessary bulk collection paths.
- Ensure centralized logging and retention cover endpoint, SaaS, Office Suite, and IaaS environments involved in sensitive data handling.
Additional notes and limits
This object is a broad collection technique rather than a specific tool or exploit. Its business relevance is strongest in environments with sensitive internal data, cloud storage, SaaS repositories, Office Suite content, or automated data pipelines. ATT&CK relationships list many campaigns and groups using this technique, but that does not by itself prove current targeting or exposure for any specific organization.
The official ATT&CK detection field is not provided. The related detection strategy name is available, but detailed analytics are not included in the supplied data. No specific products, log schemas, indicators, or guaranteed detections are supplied. Local architecture, data classification, access patterns, and logging maturity are required to assess actual risk and coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Automated Collection
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting Interpreter to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.CitationMandiant UNC3944 SMS Phishing 2023
This functionality could also be built into remote access tools.
This technique may incorporate use of other techniques such as File and Directory Discovery and Lateral Tool Transfer to identify and move files, as well as Cloud Service Dashboard and Cloud Storage Object Discovery to identify resources in cloud environments.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
