T1602 Data from Configuration Repository
High-Level Description
Adversaries may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to configure, manage, and control data on remote systems. Configuration repositories may also facilitate remote access and administration of devices.
Adversaries may target these repositories in order to collect large quantities of sensitive system administration data. Data from configuration repositories may be exposed by various protocols and software and can store a wide variety of data, much of which may align with adversary Discovery objectives.
Kill Chain Phase
- Collection (TA0009)
Platforms: Network Devices
What to Check
- Identify if Data from Configuration Repository technique is applicable to target environment
- Check Network Devices systems for indicators of Data from Configuration Repository
- Verify mitigations are bypassed or absent (6 known mitigations)
- Assess detection coverage (1 detection strategies)
How to Test
Manual Testing
Identify Attack Surface: Determine if the target environment is susceptible to Data from Configuration Repository by examining the target platforms (Network Devices).
Assess Existing Defenses: Review whether mitigations for T1602 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
Execute Test: Use tools and methods described in the MITRE ATT&CK page and external references below.
Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Remediation Guide
M1051 Update Software
Keep system images and software updated and migrate to SNMPv3.
M1054 Software Configuration
Allowlist MIB objects and implement SNMP views.
M1030 Network Segmentation
Segregate SNMP traffic on a separate management network.
M1037 Filter Network Traffic
Apply extended ACLs to block unauthorized protocols outside the trusted network.
M1031 Network Intrusion Prevention
Configure intrusion prevention devices to detect SNMP queries and commands from unauthorized sources.
M1041 Encrypt Sensitive Information
Configure SNMPv3 to use the highest level of security (authPriv) available.
Detection
Detection Strategy for Data from Configuration Repository on Network Devices
Risk Assessment
| Finding | Severity | Impact |
|---|---|---|
| Data from Configuration Repository technique applicable | Medium | Collection |
CWE Categories
| CWE ID | Title |
|---|---|
| CWE-200 | Exposure of Sensitive Information |