Data from Removable Media T1025
Tactic: Collection
Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 12 | RegistryEvent (Object create and delete) |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Security-Auditing | Event ID 6416 | A new external device was recognized by the system. |
Authoring guide
These 5 rules share fields, values, and exclusions.
Fields filtered most (7 distinct)
These fields appear most often in rule filters.
Top indicator values (9 distinct)
These values appear most often in rule predicates.
Exclusions (2 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Splunk 4 rules
- Removable Media Detected (Windows Event Log)
- Windows Process Executed From Removable Media
- Windows USBSTOR Registry Key Modification
- Windows WPDBusEnum Registry Key Modification