Anti-Forensics
Account Misuse
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF038
- Created: 28th July 2026
- Updated: 28th July 2026
- Contributor: The ITM Team
Incremental Data Collection
A subject deliberately collects organizational data in small quantities over an extended period to reduce the likelihood of detection. Rather than performing a single high-volume download or export, the subject retrieves individual files, records, messages, or other data elements across multiple sessions, systems, or working days. Each retrieval may remain below conventional alerting thresholds and may appear consistent with legitimate activity when reviewed in isolation.
Incremental Data Collection may involve slowly downloading files from network shares or collaboration platforms, accessing individual customer records, executing repeated low-volume database queries, exporting small result sets, or retrieving data through an application programming interface. The cumulative activity may result in substantial unauthorized collection while avoiding detections that focus on mass downloads, unusual transfer rates, or short-term spikes in access.
The behavior is anti-forensic where the pacing, fragmentation, or distribution of activity is intended to obscure the overall scale of collection, hinder attribution, or prevent investigators from identifying a coherent pattern. Investigators should distinguish this behavior from routine low-volume access by examining cumulative activity over extended periods, changes in the subject's access pattern, the sensitivity and novelty of the data retrieved, and whether the collection aligns with the subject's role or established working practices.