Cross-source coverage

T1091 / ATT&CK

Replication Through Removable Media

11 rules across 5 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Mobile devices may also be used to infect PCs with malware if connected via USB. This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables. For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).

Platforms
Windows
Telemetry
WinEventLog:SystemWinEventLog:SysmonWinEventLog:Microsoft-Windows-Windows Defender/Operational

How MITRE says to detect it DET0301

Removable Media Execution Chain Detection via File and Process Activity

Windows Analytic 0841

Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.

  • WinEventLog:System EventCode=1006
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Microsoft-Windows-Windows Defender/Operational Suspicious file execution on removable media path

splunk/security_content

4 rules
Detection Severity Format
Windows Process Executed From Removable Media Undefined SPL
Windows Replication Through Removable Media Undefined SPL
Windows USBSTOR Registry Key Modification Undefined SPL
Windows WPDBusEnum Registry Key Modification Undefined SPL

elastic/detection-rules

3 rules
Detection Severity Format
Execution from a Removable Media with Network Connection Low Elastic TOML
First Time Seen Removable Device Low Elastic TOML
New USB Storage Device Mounted Low Elastic TOML

elastic/protections-artifacts

2 rules
Detection Severity Format
Persistence via a Process from a Removable or Mounted ISO Device Undefined Elastic TOML
Scheduled Task from a Removable or Mounted ISO Device Undefined Elastic TOML

SigmaHQ/sigma

1 rule
Detection Severity Format
External Disk Drive Or USB Storage Device Was Recognized By The System Low Sigma

chronicle/detection-rules

1 rule
Detection Severity Format
ursnif_trojan_detection_cmd_obfuscation Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.