Replication Through Removable Media T1091

Tactics: Lateral Movement, Initial Access

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and executes. In the case of Lateral Movement, this may occur through modification of executable files stored on removable media or by copying malware and renaming it to look like a legitimate file to trick users into executing it on a separate system. In the case of Initial Access, this may occur through manual manipulation of the media, modification of systems used to initially format the media, or modification to the media's firmware itself.

Events covered

8 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 11 rules share fields, values, and exclusions.

Fields filtered most (25 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType4eq 4, ne 1start, connection_attempted, creation, deletion, mount
process.Ext.device.product_id3wildcard 2, starts_with 1USB *, Virtual DVD-ROM, Virtual Disk, USB
registry_path3contains 2, in 2, starts_with 1hklm\\software\\microsoft\\windows portable devices\\devices\\*, hklm\\system\\currentcontrolset\\enum\\swd\\wpdbusenum\\*, usbstor, hklm\\system\\currentcontrolset\\enum\\usbstor\\
registry_value_name3eq 3friendlyname
Details2contains 1, is_not_null 1:\\
TargetFilename2starts_with 1, wildcard 1?:\*\microsoft\windows\start menu\programs\startup\*, ?:\windows\system32\tasks\, ?:\windows\tasks\
TargetObject2contains 1, wildcard 1h*\software\microsoft\windows\currentversion\policies\exp..., h*\software\microsoft\windows\currentversion\run\*, h*\software\wow6432node\microsoft\windows\currentversion\..., usbstor
event.category2eq 2registry, file
host.os.type2eq 1, in 1
ClassName1eq 1diskdrive
CurrentDirectory1eq 1*
DeviceDescription1eq 1usb mass storage device
EventID1eq 16416
dropped_file_path_split_count1eq 12
event.outcome1eq 1success

Top indicator values (66 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
start
3391
EventTypeeq
connection_attempted
173
EventTypeeq
creation
158
EventTypeeq
mount
13
registry_value_nameeq
friendlyname
33
event.categoryeq
registry
214
process.Ext.device.product_idwildcard
USB *
27
process.Ext.device.product_idwildcard
Virtual DVD-ROM
28
process.Ext.device.product_idwildcard
Virtual Disk
28
registry_pathcontains
usbstor
22
registry_pathin
hklm\\software\\microsoft\\windows portable devices\\devices\\*
22
registry_pathin
hklm\\system\\currentcontrolset\\enum\\swd\\wpdbusenum\\*
22
ClassNameeq
diskdrive
1
CurrentDirectoryeq
*
1
Detailscontains
:\\
1
DeviceDescriptioneq
usb mass storage device
1
EventIDeq
6416
1
EventTypene
deletion
186
TargetFilenamestarts_with
?:\windows\system32\tasks\
16
TargetFilenamestarts_with
?:\windows\tasks\
17
TargetFilenamewildcard
?:\*\microsoft\windows\start menu\programs\startup\*
19
TargetObjectcontains
usbstor
1
TargetObjectwildcard
h*\software\microsoft\windows\currentversion\policies\explorer\run\*
111
TargetObjectwildcard
h*\software\microsoft\windows\currentversion\run\*
112
TargetObjectwildcard
h*\software\wow6432node\microsoft\windows\currentversion\policies\explorer\run\*
111
TargetObjectwildcard
h*\software\wow6432node\microsoft\windows\currentversion\run\*
111
TargetObjectwildcard
hkey_users\*\environment\userinitmprlogonscript
112
TargetObjectwildcard
hkey_users\*\software\microsoft\command processor\autorun
111
TargetObjectwildcard
hkey_users\*\software\microsoft\ctf\langbaraddin\*\filepath
111
TargetObjectwildcard
hkey_users\*\software\microsoft\internet explorer\extensions\*\exec
111

Exclusions (33 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Signatureeq
global security center
2
process.code_signature.trustedeq
true
2
CurrentDirectoryin
*\\sysvol\\*
1
CurrentDirectoryin
c:\\*
1
Hasheseq
0069d5e4690d717377410d56b56fc543edb333eb099eb591fbe561fd36c4feea
1
Hasheseq
6decdc0e295f2246d684480c10266c067cbd60c03af702505b7b3d045e81df18
1
Hasheseq
98935483ec3a9d55b45a095e1dc5a98c894aec51131390c914bf6950905629ab
1
Hasheseq
e720b05e5bc033c8cd48be3d88bf29af9ba51eeed489d6ef23d64f8b99d5648c
1
Imageeq
?:\$windows.~bt\sources\setuphost.exe
1
Imageeq
?:\program files (x86)\anvir task manager\anvir.exe
1
Imageeq
?:\program files (x86)\microsoft office\root\integration\addons\onedrivesetup.exe
1
Imageeq
?:\program files\internet explorer\iexplore.exe
1
Imageeq
?:\program files\microsoft office\root\integration\addons\onedrivesetup.exe
1
Imagewildcard
?:\program files (x86)\microsoft office\root\integration\addons\onedrivesetup.exe
1
Imagewildcard
?:\program files (x86)\microsoft onedrive\*\filesyncconfig.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Sigma 1 rule

Elastic 5 rules

Splunk 5 rules