Data from Removable Media
Where this stands
One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.
What the technique is
Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information. Some adversaries may also use Automated Collection on removable media.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN1410
Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools.
- AN1411
Adversary mounts external drive to /media or /mnt then accesses or copies targeted data via shell, cp, or tar.
- AN1412
Adversary attaches USB drive and accesses sensitive files using Finder, cp, or bash scripts.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.