1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1052 Exfiltration Over Physical Medium — Detection Rules

Detection workspace for T1052 Exfiltration Over Physical Medium: 0 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

T1052 Exfiltration Over Physical Medium

SEQUENCE(removable_media_connected, protected_file_written_to_media) WITHIN session -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0123 Detection of Data Exfiltration via Removable Media

AN0342 Analytic 0342

Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.

AN0343 Analytic 0343

Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync).

AN0344 Analytic 0344

Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip).

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1052 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.