Threat actors may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to configure, manage, and control data on remote systems. Configuration repositories may also facilitate remote access and administration of devices.
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.