Collection
Before data leaves your environment, adversaries gather it. Collection includes accessing cloud storage, email harvesting, and bulk document downloads from knowledge bases. Detecting collection activity is the last opportunity to prevent exfiltration.
Coverage
- Techniques covered
- 17
- Detection rules
- 35
- SaaS-specific rules
- 19
Threat context
How adversaries collect data before exfiltration
Collection is where adversaries identify and consolidate the data they will exfiltrate. In cloud environments, collection is rapid: bulk S3 downloads, Snowflake data exports, and mass SharePoint downloads can capture terabytes of sensitive data in minutes. For insider threats, mass email export and Confluence page bulk access are the characteristic patterns before departure.
ManySignal detects collection by correlating volume-based anomalies (10x normal download rate), access-pattern anomalies (resources not previously accessed), and time-based anomalies (bulk access outside business hours or after resignation notice). These signals, in combination, generate high-confidence collection alerts that enable intervention before exfiltration completes.
Collection techniques ManySignal detects
Data from Cloud Storage
Bulk access or download of S3 objects, Azure blobs, or GCS files.
Data from Information Repositories
Mass access to Confluence, SharePoint, Notion, or other knowledge bases.
Email Collection
Bulk email export, forwarding rule creation, or delegate access to email data.
Data Staged
Aggregating collected data in a staging location before exfiltration.
Steal Application Access Token
Obtaining OAuth access tokens from SaaS applications to collect data without credentials.
Collection: frequently asked questions
What is ATT&CK Collection (TA0009)?
Collection covers the techniques adversaries use to gather data of interest prior to exfiltration. This phase typically follows discovery and precedes exfiltration — the adversary identifies what data is valuable, collects it, stages it, and then exfiltrates it.
How does ManySignal detect mass email collection?
ManySignal ingests M365 and Google Workspace audit logs. Email collection patterns — mailbox delegation grants, search-all-mailboxes operations, or eDiscovery access by unexpected users — generate alerts. ManySignal correlates these with the user's recent authentication history to establish whether the account is compromised.
Detect data collection before exfiltration begins
ManySignal's volume-anomaly and access-pattern detection catches mass data collection across cloud storage, email, and SaaS applications.