Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0358 — Programmatic and Excessive Access to Confluence Documentation
DET0358

Programmatic and Excessive Access to Confluence Documentation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1019 Analytic 1019
SaaS

Detection of excessive or programmatic access to Confluence spaces or pages, particularly by privileged users, through a combination of access logs, API usage, and identity context. Correlates logon sessions, user roles, and abnormal document viewing or export behavior. Identifies burst access patterns and tools/scripts abusing the Confluence API for mass enumeration or data scraping.

saas:confluence access.content saas:confluence logon saas:confluence REST API access from non-browser agents
[TimeWindow] Defines the time span (e.g., 5m, 1h) in which excessive access behavior becomes suspicious.
[UserContext] Privileged user roles (e.g., domain admins) should be excluded or flagged if found accessing documentation repositories.
[AccessThreshold] The number of pages viewed or exported by a single user before triggering detection logic.
[AgentFilter] User agent strings that may indicate scripted, automated, or non-interactive access methods.

Detected Techniques

1

Collection (1)

Details

MITRE ID
DET0358
STIX ID
x-mitre-detection-strategy--3d515fbc-0ebf-4a99-b191-b6ee604acb1f
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.