Techniques › T1052 › T1052.001
T1052.001 Exfiltration over USB
exfiltration — Linux, Windows, macOS · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
0
Sigma rules tagged attack.t1052.001
0
KEV CVEs mapped here
<p>Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0220 Detection of USB-Based Data Exfiltration v1.0
AN0616 WindowsDetects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts.Tunable:
SensitiveFilePathRegexUserContextTimeWindowAN0617 LinuxDetects USB block device mount followed by file access in sensitive directories or high-volume copy operations by user-controlled processes.Tunable:MountPathCopyCommandSignatureAccessRateThresholdAN0618 macOSDetects external volume mount with Finder, Terminal, or script-initiated file copy from user profiles, sensitive folders, or cloud storage sync directories to USB.Tunable:DriveLabelFilterScriptExecutionContextVolumeMountFrequency
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1052.001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.