216.73.216.233

T1213.002: T1213.002

View on MITRE ATT&CK The MITRE Corporation · Published 16/12/2025 19:37 · Modified 16/04/2026 17:33

Essential information

MITRE technique ID
T1213.002
Confidence
100/100
Revoked
No
Published
16/12/2025 19:37
Modified
16/04/2026 17:33
Author / Source
The MITRE Corporation

Aliases

Sharepoint

Platforms

windows Office Suite

Description

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint: * Policies, procedures, and standards * Physical / logical network diagrams * System architecture diagrams * Technical system documentation * Testing / development credentials (i.e., [Unsecured Credentials](https://attack.mitre.org/techniques/T1552)) * Work / project schedules * Source code snippets * Links to network shares and other internal resources

Kill chain phases

Kill chainPhase
mitre-attack collection

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references