Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git. Once adversaries gain access to a victim network or a private code repository, they may collect sensitive information such as proprietary source code or [Unsecured Credentials](https://attack.mitre.org/techniques/T1552) contained within software's source code. Having access to software's source code may allow adversaries to develop [Exploits](https://attack.mitre.org/techniques/T1587/004), while credentials may provide access to additional resources using [Valid Accounts](https://attack.mitre.org/techniques/T1078).(Citation: Wired Uber Breach)(Citation: Krebs Adobe) **Note:** This is distinct from [Code Repositories](https://attack.mitre.org/techniques/T1593/003), which focuses on conducting [Reconnaissance](https://attack.mitre.org/tactics/TA0043) via public code repositories.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by User Training
is blocked by Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
is blocked by Audit
is blocked by User Account Management
is blocked by Multi-factor Authentication
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Secure Development Life Cycle (SDLC) Management
is blocked by Secure Engineering Principles
is blocked by Secure Software Development Practices (SSDP)
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Developer Configuration Management
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch