Hardware Additions T1200

Tactic: Initial Access

Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. Replication Through Removable Media), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (17 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
facility5eq 5pm, dhcp_snooping, mirror, port_security, sisf
mnemonic5eq 4, in 1err_disable, cfglog_loggedcmd, dhcp_snooping_untrusted_port, eth_span_session_up, ip_theft
registry_path3contains 2, in 2, starts_with 1hklm\\software\\microsoft\\windows portable devices\\devices\\*, hklm\\system\\currentcontrolset\\enum\\swd\\wpdbusenum\\*, usbstor, hklm\\system\\currentcontrolset\\enum\\usbstor\\
disable_cause2eq 2arp-inspection, psecure-violation
process_name2eq 2dhcpd, swapoff
registry_value_name2eq 2friendlyname
AdoptionTime1is_not_null 1
ClassName1eq 1diskdrive
CurrentDirectory1eq 1*
Details1contains 1:\\
DeviceDescription1eq 1usb mass storage device
Log_Type1eq 1dhcprequest
command1starts_with 1monitor session
count_1gt 11000
object_handle1is_not_null 1

Top indicator values (37 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
facilityeq
pm
22
facilityeq
dhcp_snooping
1
facilityeq
mirror
1
facilityeq
port_security
1
facilityeq
sisf
1
facilityeq
span
1
mnemoniceq
err_disable
22
mnemoniceq
cfglog_loggedcmd
1
mnemoniceq
dhcp_snooping_untrusted_port
1
mnemoniceq
eth_span_session_up
1
mnemoniceq
pktcap_start
1
mnemoniceq
psecure_violation
1
mnemoniceq
psecure_violation_vlan
1
mnemoniceq
session_up
1
registry_pathcontains
usbstor
22
registry_pathin
hklm\\software\\microsoft\\windows portable devices\\devices\\*
22
registry_pathin
hklm\\system\\currentcontrolset\\enum\\swd\\wpdbusenum\\*
22
registry_value_nameeq
friendlyname
23
ClassNameeq
diskdrive
1
CurrentDirectoryeq
*
1
Detailscontains
:\\
1
DeviceDescriptioneq
usb mass storage device
1
Log_Typeeq
dhcprequest
1
commandstarts_with
monitor session
1
count_gt
1000
1
disable_causeeq
arp-inspection
1
disable_causeeq
psecure-violation
1
mnemonicin
ip_theft
1
mnemonicin
mac_and_ip_theft
1
mnemonicin
mac_theft
1

Exclusions (2 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CurrentDirectoryin
*\\sysvol\\*
1
CurrentDirectoryin
c:\\*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Splunk 10 rules

Kusto 2 rules