Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The following is a brief list of example information that may hold potential value to an adversary and may also be found on messaging applications: * Testing / development credentials (i.e., [Chat Messages](https://attack.mitre.org/techniques/T1552/008)) * Source code snippets * Links to network shares and other internal resources * Proprietary data(Citation: Guardian Grand Theft Auto Leak 2022) * Discussions about ongoing incident response efforts(Citation: SC Magazine Ragnar Locker 2021)(Citation: Microsoft DEV-0537) In addition to exfiltrating data from messaging applications, adversaries may leverage data from chat messages in order to improve their targeting - for example, by learning more about an environment or evading ongoing incident response efforts.(Citation: Sentinel Labs NullBulge 2024)(Citation: Permiso Scattered Spider 2023)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by User Training
is blocked by Audit
is blocked by Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
is blocked by Out-of-Band Communications Channel
is blocked by Asset Inventories
is blocked by Configuration Change Control
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Encrypting Data At Rest
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Information Sharing
is blocked by Data Mining Protection
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Non-Organizational Users
is blocked by Identifier Management (User Names)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Out-of-Band Channels
is blocked by Remote Access
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum German English