{"id":"T1120","name":"Peripheral Device Discovery","url":"https://attack.mitre.org/techniques/T1120","tactics":["discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0491","stix_id":"x-mitre-detection-strategy--f273ee4a-e468-4a01-bb1a-f3a687518ded","name":"Peripheral Device Enumeration via System Utilities and API Calls","url":"https://attack.mitre.org/detectionstrategies/DET0491","analytics":[{"id":"AN1353","stix_id":"x-mitre-analytic--a986c8fd-6779-4769-895a-e6d167d9f1a9","name":"Analytic 1353","description":"Suspicious enumeration of attached peripherals via WMI, PowerShell, or low-level API calls potentially chained with removable device interactions.","url":"https://attack.mitre.org/detectionstrategies/DET0491#AN1353","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLineRegex","description":"Regex patterns for device enumeration utilities (e.g., 'Get-PnpDevice', 'wmic path Win32_USBController')"},{"field":"TimeWindow","description":"Time threshold for grouping device discovery with follow-on access or manipulation"},{"field":"UserContext","description":"Filter privileged or service accounts known to legitimately execute enumeration scripts"}],"live":true,"detection_strategies":["DET0491"],"techniques":["T1120"]},{"id":"AN1354","stix_id":"x-mitre-analytic--c8d9ad93-e4ce-4b00-89cb-8f0f6452923d","name":"Analytic 1354","description":"Enumeration of USB and other peripheral hardware via udevadm, lshw, or /sys or /proc interfaces in proximity to collection or mounting behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0491#AN1354","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open/read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"hardware_events","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"ExecutableList","description":"Set of binaries used for peripheral enumeration (e.g., 'lshw', 'lsusb', 'udevadm')"},{"field":"UserContext","description":"Tuning based on which users/scripts are authorized to query device state"}],"live":true,"detection_strategies":["DET0491"],"techniques":["T1120"]},{"id":"AN1355","stix_id":"x-mitre-analytic--479e5749-a746-4b17-9543-ca4b9d41576a","name":"Analytic 1355","description":"Execution of system utilities like 'system_profiler' and 'ioreg' to enumerate hardware components or USB devices, particularly if followed by clipboard, file, or network activity.","url":"https://attack.mitre.org/detectionstrategies/DET0491#AN1355","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"usb_devices","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"BinaryList","description":"Commands like 'system_profiler SPUSBDataType', 'ioreg -p IOUSB' that may indicate enumeration"},{"field":"TimeWindow","description":"Temporal grouping of enumeration with follow-on activity (e.g., clipboard capture, exfiltration)"}],"live":true,"detection_strategies":["DET0491"],"techniques":["T1120"]}],"live":true,"version":"1.0","techniques":["T1120"]}],"sigma_rules":[{"id":"63de06b9-a385-40b5-8b32-73f2b9ef84b6","title":"Fsutil Drive Enumeration","author":"Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'","status":"test","level":"low","date":"2022-03-29","modified":"2022-07-14","description":"Attackers may leverage fsutil to enumerated connected drives.","references":["Turla has used fsutil fsinfo drives to list connected drives.","https://github.com/elastic/detection-rules/blob/414d32027632a49fb239abb8fbbb55d3fa8dd861/rules/windows/discovery_peripheral_device.toml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1120"],"path":"rules/windows/process_creation/proc_creation_win_fsutil_drive_enumeration.yml","techniques":["T1120"],"cves":[]},{"id":"b26647de-4feb-4283-af6b-6117661283c5","title":"Powershell Suspicious Win32_PnPEntity","author":"frack113","status":"test","level":"low","date":"2021-08-23","modified":"2022-12-25","description":"Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1120/T1120.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.discovery","attack.t1120"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_win32_pnpentity.yml","techniques":["T1120"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}