1200KM / detection
T1052 Exfiltration Over Physical Medium — Detection Rules
Detection workspace for T1052 Exfiltration Over Physical Medium: 0 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
T1052 Exfiltration Over Physical Medium
SEQUENCE(removable_media_connected, protected_file_written_to_media) WITHIN session -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0123 Detection of Data Exfiltration via Removable Media
AN0342 Analytic 0342
Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.
AN0343 Analytic 0343
Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync).
AN0344 Analytic 0344
Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- Drive Creation · DC0042
- File Access · DC0055
- File Creation · DC0039
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.