{"id":"T1219.003","name":"Remote Access Hardware","url":"https://attack.mitre.org/techniques/T1219/003","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0159","stix_id":"x-mitre-detection-strategy--4a11abbc-9637-4d2e-a8ac-39fef2c0256d","name":"Detect Remote Access via USB Hardware (TinyPilot, PiKVM)","url":"https://attack.mitre.org/detectionstrategies/DET0159","analytics":[{"id":"AN0446","stix_id":"x-mitre-analytic--e1e76ffd-b452-429e-8ea0-a25ba877a2b5","name":"Analytic 0446","description":"Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements.","url":"https://attack.mitre.org/detectionstrategies/DET0159#AN0446","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=2003","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"VendorID","description":"Device vendor strings may need tuning to include additional remote hardware sources."},{"field":"SerialNumber","description":"Serial numbers for known implants can vary per campaign and may need expansion."},{"field":"TimeWindow","description":"Adjust the detection window for peripheral enumeration based on environment and operating hours."}],"live":true,"detection_strategies":["DET0159"],"techniques":["T1219.003"]},{"id":"AN0447","stix_id":"x-mitre-analytic--04e9470e-676f-4af0-add4-8103300ebd19","name":"Analytic 0447","description":"Insertion of USB-based hardware proxies (e.g., PiKVM) which register under predictable names (e.g., tinypilot) or mount under known paths (e.g., /opt/tinypilot-privileged).","url":"https://attack.mitre.org/detectionstrategies/DET0159#AN0447","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"udev events or drive enumeration involving TinyPilot paths or device classes","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"FriendlyName","description":"Different hardware may present differently; names like 'TinyPilot' may need expanding to cover custom implants."},{"field":"MountPath","description":"Path matching (e.g., /opt/tinypilot) is mutable based on distro, customization, and staging."}],"live":true,"detection_strategies":["DET0159"],"techniques":["T1219.003"]},{"id":"AN0448","stix_id":"x-mitre-analytic--fc3e13fd-cbee-4bb0-aae7-ce1e8af7d768","name":"Analytic 0448","description":"Attachment of hardware-backed USB KVM devices (e.g., TinyPilot) that enumerate new HID or serial communication interfaces with identifiable metadata.","url":"https://attack.mitre.org/detectionstrategies/DET0159#AN0448","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Hardware enumeration events via IOKit or USBMuxd showing TinyPilot or unknown keyboard/mouse","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DeviceClass","description":"Input or HID devices may be benign or malicious depending on context; tune based on environment (e.g., BYOD/dev stations)."},{"field":"SerialCorrelationDepth","description":"Correlating serials across multiple device insertions may reduce noise but requires tuning."}],"live":true,"detection_strategies":["DET0159"],"techniques":["T1219.003"]}],"live":true,"version":"1.0","techniques":["T1219.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}