Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

External device of a code-execution or network class attached

Matches Security EventID 6416, "a new external device was recognized by the system", narrowed to the device classes that can carry a hardware addition rather than merely store data: human interface devices (keystroke injection), network adapters (rogue USB-NIC or adversary-in-the-middle tap) and disk or SCSI controllers (DMA-capable and mass-storage arrivals). The logsource is the Security channel, so `EventID` is matched explicitly. MITRE's AN0185 is a correlation — device arrival, then a volume mount or process spawn by the same session inside TimeWindow, optionally a new MAC taking a DHCP lease — and none of that is expressible in Sigma, so this is the arrival leg only. Coverage for this technique is inherently weak: 6416 records that a device appeared, not whether it is malicious, and the VID/PID allowlisting MITRE relies on has to happen outside the rule. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0069, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: External device of a code-execution or network class attachedid: 04e9bd1e-47a5-40b9-9650-254b34a31f48status: experimentaldescription: |  Matches Security EventID 6416, "a new external device was recognized by the  system", narrowed to the device classes that can carry a hardware addition  rather than merely store data: human interface devices (keystroke injection),  network adapters (rogue USB-NIC or adversary-in-the-middle tap) and disk or  SCSI controllers (DMA-capable and mass-storage arrivals). The logsource is the  Security channel, so `EventID` is matched explicitly. MITRE's AN0185 is a  correlation — device arrival, then a volume mount or process spawn by the same  session inside TimeWindow, optionally a new MAC taking a DHCP lease — and none  of that is expressible in Sigma, so this is the arrival leg only. Coverage for  this technique is inherently weak: 6416 records that a device appeared, not  whether it is malicious, and the VID/PID allowlisting MITRE relies on has to  happen outside the rule.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0069, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1200  - https://attack.mitre.org/detectionstrategies/DET0069author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.initial-access  - attack.t1200logsource:  product: windows  service: securitydetection:  selection:    EventID: 6416    ClassName:      - 'HIDClass'      - 'Net'      - 'DiskDrive'      - 'SCSIAdapter'  condition: selectionfalsepositives:  - "Everyday peripheral use on workstations and laptops. A user plugging in a keyboard, mouse, headset, dock or USB hub emits HIDClass arrivals constantly, and a dock also brings a Net-class adapter with it. MITRE's TrustedDeviceVIDPID and TrustedMACs knobs are the intended filter, and neither is available in the 6416 fields this rule matches, so the practical deployment is to scope the rule to the ServerClassesNoUSB population — domain controllers, hypervisors and other hosts where any external attach is policy-violating."  - "Corporate imaging, repair and provisioning work, where technicians attach external drives, USB-to-Ethernet adapters and bootable media as a routine part of the job, generating DiskDrive and Net arrivals in bulk during a build window."  - "Virtual and remote-desktop sessions that redirect client peripherals into the guest, which surface as fresh device recognitions on the guest at every logon even though no physical hardware was added."  - "Docking and undocking a laptop, which replays the whole peripheral set through 6416 several times a day per user."level: low

Sentinel · KQL

Run this as a search.

SecurityEvent| where (EventID == 6416 and (ClassName =~ "HIDClass" or ClassName =~ "Net" or ClassName =~ "DiskDrive" or ClassName =~ "SCSIAdapter"))

Splunk · SPL

Run this as a search.

index=* (EventID="6416" AND (ClassName="HIDClass" OR ClassName="Net" OR ClassName="DiskDrive" OR ClassName="SCSIAdapter"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (event.code == 6416 AND (TO_LOWER(winlog.event_data.ClassName) == "hidclass" OR TO_LOWER(winlog.event_data.ClassName) == "net" OR TO_LOWER(winlog.event_data.ClassName) == "diskdrive" OR TO_LOWER(winlog.event_data.ClassName) == "scsiadapter"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="EventID" type="pcre2">(?i)^6416$</field>    <field name="ClassName" type="pcre2">(?i)(^HIDClass$|^Net$|^DiskDrive$|^SCSIAdapter$)</field>    <description>External device of a code-execution or network class attached</description>    <mitre>      <id>T1200</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.