1200KM / detection
T1200 Hardware Additions — Detection Rules
Detection workspace for T1200 Hardware Additions: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- USB Device Plugged · test · low · {"product":"windows","service":"driver-framework","definition":"Requires enabling and collection of the Microsoft-Windows-DriverFrameworks-UserMode/Operational eventlog"}
- Device Installation Blocked · test · medium · {"service":"security","product":"windows"}
- External Disk Drive Or USB Storage Device Was Recognized By The System · test · low · {"product":"windows","service":"security"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0069 Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)
AN0185 Analytic 0185
Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata.
AN0186 Analytic 0186
Chain: (1) udev / kernel logs show hot-plug (USB/Thunderbolt/PCIe); (2) block device created by udisks/diskarbitration; (3) optional: new network interface or DHCP lease observed. Correlate /var/log/messages|syslog, auditd SYSCALL open/creat on /dev, and DHCP/Zeek.
AN0187 Analytic 0187
Chain: (1) unified logs report IOUSBHost/IOThunderbolt device arrival; (2) diskarbitrationd attaches a new volume; (3) optional: config profile manipulation or new network interface MAC obtains a lease. Correlate unifiedlogs (subsystems: IOUSBHost, IOKit, diskarbitrationd), FSEvents, and DHCP/Zeek.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- Drive Creation · DC0042
- Driver Load · DC0079
- File Creation · DC0039
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.