GCP bigquery.jobs.insert
Submits a BigQuery query, load, extract, or copy job.
The adversary is trying to gather data of interest to their goal.
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary’s objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.
In cloud environments, adversaries collect data from storage services (S3, Blob Storage, GCS), databases, and snapshots. They may create copies of EBS volumes or database snapshots, query data warehouses, or access logging buckets that contain sensitive operational data.
View Collection on MITRE ATT&CK →Explore this tactic in the map.
Submits a BigQuery query, load, extract, or copy job.
Requests a Cloud SQL export to Cloud Storage.
Requests a server-side copy of an Azure blob.
Copies an S3 object to another key or bucket.
Starts creation of a manual RDS DB instance snapshot.
Starts creation of an EBS-backed AMI from an EC2 instance.
Starts an eligible EC2 instance export to an S3 bucket.
Starts creation of a point-in-time EBS volume snapshot.
Removes an S3 bucket policy without resetting other access controls.
Retrieves an S3 object or selected version, optionally as a byte range.
Requests temporary access to an Azure managed disk.
Requests temporary access to an Azure managed-disk snapshot.
Requests export of Azure SQL Database schema and data to a BACPAC in Blob Storage.
Replaces an S3 bucket ACL where ACLs are enabled.
Sets the four bucket-level S3 Block Public Access controls.
Creates a new RDS DB instance from a snapshot.
Starts an RDS data export to Amazon S3.