1200KM / detection
T1458 Replication Through Removable Media — Detection Rules
Detection workspace for T1458 Replication Through Removable Media: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0691 Detection of Replication Through Removable Media
AN1802 Analytic 1802
Defender correlates a causal chain where a device transitions into USB debugging or file transfer mode after a physical connection event, followed by application installation, file replication, or execution originating from the USB interface rather than the application store ecosystem.
AN1803 Analytic 1803
Defender correlates a chain where a device establishes a new trusted USB host pairing or enters developer/debug configuration state, followed by device data extraction activity, configuration manipulation, or abnormal application behavior shortly after the pairing event.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Permission · DC0114
- File Creation · DC0039
- Host Status · DC0018
- OS API Execution · DC0021
- Process Creation · DC0032
- Protected Configuration · DC0115
- System Settings · DC0118
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.