kevmap

TechniquesT1091 › AN0841

AN0841 Analytic 0841

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.</p>
Detects
T1091 Replication Through Removable Media
Part of
DET0301 Removable Media Execution Chain Detection via File and Process Activity

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SystemEventCode=1006DC0042 Drive Creation
WinEventLog:SysmonEventCode=11DC0039 File Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:Microsoft-Windows-Windows Defender/OperationalSuspicious file execution on removable media pathDC0055 File Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
DriveLetterMatchDetect activity on mounted drives typically used by USB (e.g., E:, F:, G:). Tune based on enterprise usage.
FileExecutionWindowSet timing threshold for execution shortly after drive mount (e.g., < 5 minutes).
ParentProcessRestrict detection to suspicious process lineage like explorer.exe, powershell.exe, or unsigned binaries.
FileEntropyUse entropy thresholding to detect packed/obfuscated payloads dropped to removable media.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2024-50302Linux KernelMapped
CVE-2024-53104Linux KernelMapped
CVE-2024-53150Linux KernelMapped
CVE-2024-53197Linux KernelMapped
CVE-2025-24985Microsoft WindowsMapped
CVE-2025-24991Microsoft WindowsMapped