External device of a code-execution or network class attached
Matches Security EventID 6416, "a new external device was recognized by the system", narrowed to the device classes that can carry a hardware addition rather than merely store data: human interface devices (keystroke injection), network adapters (rogue USB-NIC or adversary-in-the-middle tap) and disk or SCSI controllers (DMA-capable and mass-storage arrivals). The logsource is the Security channel, so `EventID` is matched explicitly. MITRE's AN0185 is a correlation — device arrival, then a volume mount or process spawn by the same session inside TimeWindow, optionally a new MAC taking a DHCP lease — and none of that is expressible in Sigma, so this is the arrival leg only. Coverage for this technique is inherently weak: 6416 records that a device appeared, not whether it is malicious, and the VID/PID allowlisting MITRE relies on has to happen outside the rule. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0069, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full descriptionShow less
The detection
The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.
detection.yml
title: External device of a code-execution or network class attachedid: 04e9bd1e-47a5-40b9-9650-254b34a31f48status: experimentaldescription: | Matches Security EventID 6416, "a new external device was recognized by the system", narrowed to the device classes that can carry a hardware addition rather than merely store data: human interface devices (keystroke injection), network adapters (rogue USB-NIC or adversary-in-the-middle tap) and disk or SCSI controllers (DMA-capable and mass-storage arrivals). The logsource is the Security channel, so `EventID` is matched explicitly. MITRE's AN0185 is a correlation — device arrival, then a volume mount or process spawn by the same session inside TimeWindow, optionally a new MAC taking a DHCP lease — and none of that is expressible in Sigma, so this is the arrival leg only. Coverage for this technique is inherently weak: 6416 records that a device appeared, not whether it is malicious, and the VID/PID allowlisting MITRE relies on has to happen outside the rule. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0069, not hand-written and not tested by its author. Any lab result is on this rule's own page.references: - https://attack.mitre.org/techniques/T1200 - https://attack.mitre.org/detectionstrategies/DET0069author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags: - attack.initial-access - attack.t1200logsource: product: windows service: securitydetection: selection: EventID: 6416 ClassName: - 'HIDClass' - 'Net' - 'DiskDrive' - 'SCSIAdapter' condition: selectionfalsepositives: - "Everyday peripheral use on workstations and laptops. A user plugging in a keyboard, mouse, headset, dock or USB hub emits HIDClass arrivals constantly, and a dock also brings a Net-class adapter with it. MITRE's TrustedDeviceVIDPID and TrustedMACs knobs are the intended filter, and neither is available in the 6416 fields this rule matches, so the practical deployment is to scope the rule to the ServerClassesNoUSB population — domain controllers, hypervisors and other hosts where any external attach is policy-violating." - "Corporate imaging, repair and provisioning work, where technicians attach external drives, USB-to-Ethernet adapters and bootable media as a routine part of the job, generating DiskDrive and Net arrivals in bulk during a build window." - "Virtual and remote-desktop sessions that redirect client peripherals into the guest, which surface as fresh device recognitions on the guest at every logon even though no physical hardware was added." - "Docking and undocking a laptop, which replays the whole peripheral set through 6416 several times a day per user."level: lowSentinel · KQL
Run this as a search.
SecurityEvent| where (EventID == 6416 and (ClassName =~ "HIDClass" or ClassName =~ "Net" or ClassName =~ "DiskDrive" or ClassName =~ "SCSIAdapter"))
Splunk · SPL
Run this as a search.
index=* (EventID="6416" AND (ClassName="HIDClass" OR ClassName="Net" OR ClassName="DiskDrive" OR ClassName="SCSIAdapter"))Elastic · ES|QL
Run this as a search.
FROM logs-*| WHERE (event.code == 6416 AND (TO_LOWER(winlog.event_data.ClassName) == "hidclass" OR TO_LOWER(winlog.event_data.ClassName) == "net" OR TO_LOWER(winlog.event_data.ClassName) == "diskdrive" OR TO_LOWER(winlog.event_data.ClassName) == "scsiadapter"))
Wazuh · XML rule
Deploy to your manager — this is a rule, not a search.
<group name="sigma,windows,"> <!-- Rule ids must be unique on your manager; 100000+ is the user range. --> <rule id="100000" level="5"> <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. --> <field name="EventID" type="pcre2">(?i)^6416$</field> <field name="ClassName" type="pcre2">(?i)(^HIDClass$|^Net$|^DiskDrive$|^SCSIAdapter$)</field> <description>External device of a code-execution or network class attached</description> <mitre> <id>T1200</id> </mitre> </rule></group>
Verdicts · reactions · comments
Community
Verdicts from engineers who actually deployed it, and the conversation around it.
Nobody has run this in a real environment and said what happened.
Verdicts from engineers who deployed it
0 castNo verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.
Log in to report a verdict.
Log in to join the discussion.
No comments yet. Someone who deploys this will have something to say about it.