{"id":"T1052","name":"Exfiltration Over Physical Medium","url":"https://attack.mitre.org/techniques/T1052","tactics":["exfiltration"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0123","stix_id":"x-mitre-detection-strategy--7ac4c58e-73de-4da1-8fc3-c2ccc511d884","name":"Detection of Data Exfiltration via Removable Media","url":"https://attack.mitre.org/detectionstrategies/DET0123","analytics":[{"id":"AN0342","stix_id":"x-mitre-analytic--198d4196-25f0-4e28-a95b-c89709f452ab","name":"Analytic 0342","description":"Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.","url":"https://attack.mitre.org/detectionstrategies/DET0123#AN0342","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:System","channel":"EventCode=1006, 10001","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"DriveTypeFilter","description":"Filter on removable (e.g., USB) drives only."},{"field":"ProcessNameExclusionList","description":"Exclude known, approved backup or sync utilities."},{"field":"TimeWindow","description":"Limit correlation of file access and device mount to a defined window (e.g., <5 minutes)."}],"live":true,"detection_strategies":["DET0123"],"techniques":["T1052"]},{"id":"AN0343","stix_id":"x-mitre-analytic--4e288214-93b3-48a7-b51e-2b0136db8540","name":"Analytic 0343","description":"Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync).","url":"https://attack.mitre.org/detectionstrategies/DET0123#AN0343","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"device event logs","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"MountPointPattern","description":"Monitor mount points like /media, /mnt, or /run/media."},{"field":"UserGroupScope","description":"Restrict detection to non-root or unexpected users."},{"field":"AccessVolumeThreshold","description":"Alert on large file access or copy events."}],"live":true,"detection_strategies":["DET0123"],"techniques":["T1052"]},{"id":"AN0344","stix_id":"x-mitre-analytic--acaabb0b-6cfc-45cd-8bd9-08ad49e1096c","name":"Analytic 0344","description":"Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip).","url":"https://attack.mitre.org/detectionstrategies/DET0123#AN0344","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Volume Mount + File Read","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"file_events","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-osquery"},{"name":"fs:fsusage","channel":"file system activity monitor","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"VolumeNamePattern","description":"Detect suspicious or unrecognized drive labels (e.g., UNTITLED, BACKUP_VOL)."},{"field":"ProcessOrigin","description":"Detect CLI-based copy operations vs. expected GUI usage."},{"field":"UserSessionCheck","description":"Alert if process and session context are mismatched (e.g., script from screensaver context)."}],"live":true,"detection_strategies":["DET0123"],"techniques":["T1052"]}],"live":true,"version":"1.0","techniques":["T1052"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}