MITRE ATT&CK Technique
T1119Automated Collection
- First Reported
- Sep 8, 2025
- Latest Reported
- Jul 22, 2026
Official Description
Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059) to search for and copy information fitting set criteria such as file type, location, or name at specific time intervals.
In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.(Citation: Mandiant UNC3944 SMS Phishing 2023)
This functionality could also be built into remote access tools.
This technique may incorporate use of other techniques such as [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) and [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570) to identify and move files, as well as [Cloud Service Dashboard](https://attack.mitre.org/techniques/T1538) and [Cloud Storage Object Discovery](https://attack.mitre.org/techniques/T1619) to identify resources in cloud environments.
In cloud-based environments, adversaries may also use cloud APIs, data pipelines, command line interfaces, or extract, transform, and load (ETL) services to automatically collect data.(Citation: Mandiant UNC3944 SMS Phishing 2023)
This functionality could also be built into remote access tools.
This technique may incorporate use of other techniques such as [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) and [Lateral Tool Transfer](https://attack.mitre.org/techniques/T1570) to identify and move files, as well as [Cloud Service Dashboard](https://attack.mitre.org/techniques/T1538) and [Cloud Storage Object Discovery](https://attack.mitre.org/techniques/T1619) to identify resources in cloud environments.
- Tactics
- Collection
- Platforms
- IaaS, Linux, macOS, Office Suite, SaaS, Windows
- MITRE Version
- 1.4
- Last Modified
- May 12, 2026
Reported Context (6)
- The scanner automatically searched for secrets, while workflows monitored and collected newly written result files. Compromised GitHub Actions Repositories Fuel cPanel/WHM Exploitation and Credential Theft
- FileFiend automatically enumerated local drives and SMB network shares for data collection. Exposed Staging Server Reveals Data from Ababil of Minab Campaign, Including LA Metro Records
- Automatically discovered collector modules run in parallel and merge their harvested results into a single output object. TeamPCP Python Toolkit Uses FIRESCALE and Victim GitHub Accounts to Survive C2 Disruption
- print_param.py automatically reads and prints incoming HTTP POST bodies on port 9008. CVE-2025-32975 KACE SMA Breach Revealed HIQ Data and 60+ Downstream Clients
- The bandwidth profiler automatically obtains victim location and public IP information, measures upstream throughput, and reports the result to C2. Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet
CVE (4)
Malware (11)
People (6)
Threat Actors (8)
MITRE ATT&CK (83)
Vendors (19)
Products (55)
Tools (29)
Industries (16)
Countries (8)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.