{"id":"T1025","name":"Data from Removable Media","url":"https://attack.mitre.org/techniques/T1025","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0511","stix_id":"x-mitre-detection-strategy--a5800f15-f024-4701-912a-20d7e1cb465a","name":"Detection of Data Access and Collection from Removable Media","url":"https://attack.mitre.org/detectionstrategies/DET0511","analytics":[{"id":"AN1410","stix_id":"x-mitre-analytic--4385bff9-e730-48cd-bdfc-43de56c302aa","name":"Analytic 1410","description":"Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools.","url":"https://attack.mitre.org/detectionstrategies/DET0511#AN1410","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:System","channel":"EventCode=2003","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"VolumeLabel","description":"Can tune based on known removable device labels or whitelist"},{"field":"TimeWindow","description":"Controls timing between device mount and sensitive file access"},{"field":"TargetFileType","description":"Tune for sensitive file extensions (e.g., .docx, .pdf, .csv)"}],"live":true,"detection_strategies":["DET0511"],"techniques":["T1025"]},{"id":"AN1411","stix_id":"x-mitre-analytic--5312ddd0-dd58-4bcb-afc0-7a05a6b2df42","name":"Analytic 1411","description":"Adversary mounts external drive to /media or /mnt then accesses or copies targeted data via shell, cp, or tar.","url":"https://attack.mitre.org/detectionstrategies/DET0511#AN1411","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, read, mount","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"journald:systemd","channel":"udisks2 or udevd logs","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"journald-systemd"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"MountPathRegex","description":"Filter for unexpected or user-defined mount locations (e.g., /media/usb*)"},{"field":"AccessMask","description":"Tune based on read/write access types seen during collection"}],"live":true,"detection_strategies":["DET0511"],"techniques":["T1025"]},{"id":"AN1412","stix_id":"x-mitre-analytic--9abfb75c-2051-4549-b458-f09c4e6f4ad3","name":"Analytic 1412","description":"Adversary attaches USB drive and accesses sensitive files using Finder, cp, or bash scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0511#AN1412","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream --predicate 'eventMessage contains \"USBMSC\"'","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"file reads/writes from /Volumes/","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"fs-fsusage"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"VolumePath","description":"Tune by filtering removable media mounted under /Volumes"},{"field":"UserContext","description":"Correlate activity to admin or service accounts for priority"}],"live":true,"detection_strategies":["DET0511"],"techniques":["T1025"]}],"live":true,"version":"1.0","techniques":["T1025"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}