Skip to main content

Metric collection

CCC.Monitor.CP01

Gathering numerical (quantitative) data points about the performance, health, or behaviour of systems, applications or infrastructure.

Related Threats

IDTitleDescription
CCC.Monitor.TH01Capture Personal Identifiable InformationUnauthorised viewers may get access to PII if it is incorrectly collected by monitoring systems through metrics or tracing.
CCC.Monitor.TH05Data Exfiltration Through Tampered MetricsIf a malicious actor is able to make changes to the metrics being collected, it could be used to encrypt and or compress sensitive data and bypass controls preventing exfiltration. The data can then be staged in the monitoring system and exfiltrated in bulk at a later point in time
CCC.Monitor.TH06Cost Exhaustion Through Tampered Alerts or Metrics CollectionMonitoring systems are expected to generate traffic, but it a malicious actor were to change alerts that were being fired at an API which charged per requests or generate large volumes of metric data which would then need to be stored and processed, or even triggering resource scaling, this would cause an increase in cloud bill.
CCC.Monitor.TH07Trigger Malicious CodeIf a malicious actor is able to create new triggers, they would be able to use valid metric data to trigger malicious actions and re-compromise a newly replaced container or compute instance.