Peripheral Device Discovery T1120

Tactic: Discovery

Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 5 rules share fields, values, and exclusions.

Fields filtered most (11 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
OriginalFileName2eq 2fsutil.exe
ScriptBlockText2contains 1, eq 1, in 1get-audiodevice, get-microphoneaudio, mcisendstring, win32_pnpentity
CommandLine1contains 1drives
EventID1eq 14688
Image1ends_with 1\fsutil.exe
Type1eq 1
event.category1eq 1process
event.type1eq 1start
host.os.type1eq 1
process.args1eq 1drives, fsinfo
process_name1eq 1fsutil.exe

Top indicator values (22 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
OriginalFileNameeq
fsutil.exe
26
CommandLinecontains
drives
1
EventIDeq
4688
1317
Imageends_with
\fsutil.exe
15
ScriptBlockTextcontains
win32_pnpentity
1
ScriptBlockTexteq
get-audiodevice
1
ScriptBlockTexteq
get-microphoneaudio
1
ScriptBlockTexteq
recording
1
ScriptBlockTexteq
set-audiodevice
1
ScriptBlockTexteq
windowsaudiodevice-powershell-cmdlet
1
ScriptBlockTexteq
winmm.dll
1
ScriptBlockTextin
mcisendstring
1
ScriptBlockTextin
mcisendstringa
1
ScriptBlockTextin
mcisendstringw
1
ScriptBlockTextin
waveingetnumdevs
1
ScriptBlockTextin
waveinopen
1
ScriptBlockTextin
waveinstart
1
event.categoryeq
process
1142
event.typeeq
start
11078
process.argseq
drives
1
process.argseq
fsinfo
1
process_nameeq
fsutil.exe
17

Exclusions (3 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
ScriptBlockTexteq
powersploitindicators
1
ScriptBlockTexteq
sentinelbreakpoints
1
ScriptBlockTexteq
set-psbreakpoint
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Sigma 2 rules

Elastic 2 rules

Splunk 1 rule