{"id":"T1052.001","name":"Exfiltration over USB","url":"https://attack.mitre.org/techniques/T1052/001","tactics":["exfiltration"],"platforms":["Linux","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0220","stix_id":"x-mitre-detection-strategy--f6dd18b4-8534-4883-8d57-80655418bed4","name":"Detection of USB-Based Data Exfiltration","url":"https://attack.mitre.org/detectionstrategies/DET0220","analytics":[{"id":"AN0616","stix_id":"x-mitre-analytic--67ff7cc5-7b9b-4d15-b115-b55c3d164c64","name":"Analytic 0616","description":"Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0220#AN0616","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:System","channel":"EventCode=2003","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"SensitiveFilePathRegex","description":"Match data staging or export paths (e.g., *.docx, *.csv, *.db) to USB volume letters."},{"field":"UserContext","description":"Limit to users who do not normally use removable devices (e.g., service accounts)."},{"field":"TimeWindow","description":"Correlate events within a short period following USB insert (e.g., 5–10 minutes)."}],"live":true,"detection_strategies":["DET0220"],"techniques":["T1052.001"]},{"id":"AN0617","stix_id":"x-mitre-analytic--9cf3c7bb-296e-445a-ba30-012060b9ccac","name":"Analytic 0617","description":"Detects USB block device mount followed by file access in sensitive directories or high-volume copy operations by user-controlled processes.","url":"https://attack.mitre.org/detectionstrategies/DET0220#AN0617","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"Kernel Device Events - USB Block Devices","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"MountPath","description":"Look for /media/, /mnt/, /run/media/ paths associated with removable storage."},{"field":"CopyCommandSignature","description":"Detect rsync, cp, tar, zip activity writing to USB mount point."},{"field":"AccessRateThreshold","description":"Define abnormal access patterns (e.g., >100 files in <5 min)."}],"live":true,"detection_strategies":["DET0220"],"techniques":["T1052.001"]},{"id":"AN0618","stix_id":"x-mitre-analytic--9d7fd025-d8eb-48ab-8fca-df6b09761aec","name":"Analytic 0618","description":"Detects external volume mount with Finder, Terminal, or script-initiated file copy from user profiles, sensitive folders, or cloud storage sync directories to USB.","url":"https://attack.mitre.org/detectionstrategies/DET0220#AN0618","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Volume Mount + Process Trace + File Read","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"Disk Activity Tracing","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"DriveLabelFilter","description":"Flag removable volumes with suspicious or default names (e.g., NO NAME, BACKUP_01)."},{"field":"ScriptExecutionContext","description":"Watch for shell or AppleScript execution tied to USB copy."},{"field":"VolumeMountFrequency","description":"Detect repeated or abnormal device mounts during work hours."}],"live":true,"detection_strategies":["DET0220"],"techniques":["T1052.001"]}],"live":true,"version":"1.0","techniques":["T1052.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}