Cross-source coverage
T1091 / ATT&CK
Replication Through Removable Media
11 rules across 5 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.
Mobile devices may also be used to infect PCs with malware if connected via USB. This infection may be achieved using devices (Android, iOS, etc.) and, in some instances, USB charging cables. For example, when a smartphone is connected to a system, it may appear to be mounted similar to a USB-connected disk drive. If malware that is compatible with the connected system is on the mobile device, the malware could infect the machine (especially if Autorun features are enabled).
- Tactics
- Lateral Movement · Initial Access
- Platforms
- Windows
- Telemetry
-
WinEventLog:SystemWinEventLog:SysmonWinEventLog:Microsoft-Windows-Windows Defender/Operational
How MITRE says to detect it DET0301
Removable Media Execution Chain Detection via File and Process Activity
Windows Analytic 0841
Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.
WinEventLog:SystemEventCode=1006WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=1WinEventLog:Microsoft-Windows-Windows Defender/OperationalSuspicious file execution on removable media path
splunk/security_content
4 rules| Detection | Severity | Format |
|---|---|---|
| Windows Process Executed From Removable Media | Undefined | SPL |
| Windows Replication Through Removable Media | Undefined | SPL |
| Windows USBSTOR Registry Key Modification | Undefined | SPL |
| Windows WPDBusEnum Registry Key Modification | Undefined | SPL |
elastic/detection-rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Execution from a Removable Media with Network Connection | Low | Elastic TOML |
| First Time Seen Removable Device | Low | Elastic TOML |
| New USB Storage Device Mounted | Low | Elastic TOML |
elastic/protections-artifacts
2 rules| Detection | Severity | Format |
|---|---|---|
| Persistence via a Process from a Removable or Mounted ISO Device | Undefined | Elastic TOML |
| Scheduled Task from a Removable or Mounted ISO Device | Undefined | Elastic TOML |
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| External Disk Drive Or USB Storage Device Was Recognized By The System | Low | Sigma |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| ursnif_trojan_detection_cmd_obfuscation | Undefined | YARA-L |