Collection Detection Rules
The adversary is trying to gather data of interest to their goal. Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
df00tech ships 63 production-ready detection rules mapped to the Collection tactic (TA0009). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Collection detections (63)
- CVE-2017-7921 Hikvision Improper Authentication Exploitation (CVE-2017-7921)
- CVE-2025-8110 Gogs Path Traversal Vulnerability (CVE-2025-8110)
- CVE-2025-11371 Gladinet CentreStack/Triofox Unauthorized File/Directory Access (CVE-2025-11371)
- CVE-2025-31125 CVE-2025-31125: Vite Dev Server Improper Access Control
- CVE-2025-48700 Zimbra Collaboration Suite XSS Exploitation (CVE-2025-48700)
- CVE-2025-58360 OSGeo GeoServer XXE Injection Exploitation Attempt
- CVE-2025-66376 Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Exploitation
- CVE-2025-68461 RoundCube Webmail Cross-Site Scripting (XSS) Exploitation Attempt
- CVE-2026-0755 CVE-2026-0755: gemini-mcp-tool OS Command Injection and File Exfiltration via Prompt Quoting
- CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read (CVE-2026-3055)
- CVE-2026-15409 SonicWall SMA1000 Server-Side Request Forgery Exploitation (CVE-2026-15409)
- CVE-2026-20133 Cisco Catalyst SD-WAN Manager Sensitive Information Exposure (CVE-2026-20133)
- CVE-2026-20253 CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function
- CVE-2026-32966 Apache DolphinScheduler DataSource API Missing Authorization - Arbitrary Metadata Disclosure (CVE-2026-32966)
- CVE-2026-42208 BerriAI LiteLLM SQL Injection Exploitation (CVE-2026-42208)
- CVE-2026-44935 Rancher Fleet Cross-Namespace Secret Disclosure via Unvalidated valuesFrom in Helm Deployer (CVE-2026-44935)
- CVE-2026-45262 FacturaScripts REST API Authenticated SQL Injection via Where::sqlColumn Parenthesis Bypass (CVE-2026-45262)
- CVE-2026-54350 Budibase Anonymous NoSQL Operator Injection via Published-App Query Templates
- CVE-2026-55255 Langflow IDOR: Unauthorized Access to Another User's Flow via /api/v1/responses
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- T1005 Data from Local System
- T1025 Data from Removable Media
- T1039 Data from Network Shared Drive
- T1056 Input Capture
- T1056.001 Keylogging
- T1056.002 GUI Input Capture
- T1056.003 Web Portal Capture
- T1056.004 Credential API Hooking
- T1074 Data Staged
- T1074.001 Local Data Staging
- T1074.002 Remote Data Staging
- T1113 Screen Capture
- T1114 Email Collection
- T1114.001 Local Email Collection
- T1114.002 Remote Email Collection
- T1114.003 Email Forwarding Rule
- T1115 Clipboard Data
- T1119 Automated Collection
- T1123 Audio Capture
- T1125 Video Capture
- T1185 Browser Session Hijacking
- T1213 Data from Information Repositories
- T1213.001 Confluence
- T1213.002 Sharepoint
- T1213.003 Code Repositories
- T1213.004 Customer Relationship Management Software
- T1213.005 Messaging Applications
- T1213.006 Databases
- T1530 Data from Cloud Storage
- T1557 Adversary-in-the-Middle
- T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
- T1557.002 ARP Cache Poisoning
- T1557.003 DHCP Spoofing
- T1557.004 Evil Twin
- T1560 Archive Collected Data
- T1560.001 Archive via Utility
- T1560.002 Archive via Library
- T1560.003 Archive via Custom Method
- T1602 Data from Configuration Repository
- T1602.001 SNMP (MIB Dump)
- T1602.002 Network Device Configuration Dump
- THREAT-BEC-OAuthDeviceCode Business Email Compromise via OAuth Device Code Flow Phishing
- THREAT-M365-SuspiciousOAuthConsent Suspicious OAuth Application Consent Grant in Microsoft 365
Related tactics
266 detections
225 detections