{"id":"T1091","name":"Replication Through Removable Media","url":"https://attack.mitre.org/techniques/T1091","tactics":["lateral-movement","initial-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0301","stix_id":"x-mitre-detection-strategy--8225c396-cbf9-499a-b94d-bdc7a1f07458","name":"Removable Media Execution Chain Detection via File and Process Activity","url":"https://attack.mitre.org/detectionstrategies/DET0301","analytics":[{"id":"AN0841","stix_id":"x-mitre-analytic--12c748a0-3ce9-4fd2-8a65-f4362b69cafd","name":"Analytic 0841","description":"Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.","url":"https://attack.mitre.org/detectionstrategies/DET0301#AN0841","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=1006","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-Windows Defender/Operational","channel":"Suspicious file execution on removable media path","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-microsoft-windows-windows-defender-operational"}],"mutable_elements":[{"field":"DriveLetterMatch","description":"Detect activity on mounted drives typically used by USB (e.g., E:, F:, G:). Tune based on enterprise usage."},{"field":"FileExecutionWindow","description":"Set timing threshold for execution shortly after drive mount (e.g., < 5 minutes)."},{"field":"ParentProcess","description":"Restrict detection to suspicious process lineage like explorer.exe, powershell.exe, or unsigned binaries."},{"field":"FileEntropy","description":"Use entropy thresholding to detect packed/obfuscated payloads dropped to removable media."}],"live":true,"detection_strategies":["DET0301"],"techniques":["T1091"]}],"live":true,"version":"1.0","techniques":["T1091"]}],"sigma_rules":[{"id":"f69a87ea-955e-4fb4-adb2-bb9fd6685632","title":"External Disk Drive Or USB Storage Device Was Recognized By The System","author":"Keith Wright","status":"test","level":"low","date":"2019-11-20","modified":"2024-02-09","description":"Detects external disk drives or plugged-in USB devices.","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-6416"],"logsource":{"product":"windows","service":"security"},"tags":["attack.t1091","attack.t1200","attack.lateral-movement","attack.initial-access"],"path":"rules/windows/builtin/security/win_security_external_device.yml","techniques":["T1091","T1200"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-53150","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-53197","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24991","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24985","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-50302","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-53104","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}