1200KM / simulation
T1120 Peripheral Device Discovery — Attack Simulation
Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.
Technique description
Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Win32_PnPEntity Hardware Inventory
Procedure 2cb4dbf2-2dca-4597-8678-4d39d207a3a5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Peripheral Device Discovery via fsutil
Procedure 424e18fd-48b8-4201-8d3a-bf591523a686; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get Printer Device List via PowerShell Command
Procedure 5c876daf-db1e-41cf-988d-139a7443ccd4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - printercheck
Procedure cb6e76ca-861e-4a7f-be08-564caa3e6f75; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.