{"id":"T1674","name":"Input Injection","url":"https://attack.mitre.org/techniques/T1674","tactics":["execution"],"platforms":["Windows","macOS","Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0568","stix_id":"x-mitre-detection-strategy--f54b8799-acfd-4df4-a2c4-e83071750bde","name":"Detection Strategy for Input Injection","url":"https://attack.mitre.org/detectionstrategies/DET0568","analytics":[{"id":"AN1567","stix_id":"x-mitre-analytic--0f05915c-e146-4921-840b-1a08774ca4d2","name":"Analytic 1567","description":"Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards.","url":"https://attack.mitre.org/detectionstrategies/DET0568#AN1567","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=2003","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"AuthorizedUSBDevices","description":"List of known, legitimate USB vendor/product IDs authorized for use in the enterprise."},{"field":"ExecutionTimeWindow","description":"Restrict detection to times when no user is logged in or activity is outside business hours."},{"field":"ParentProcessWhitelist","description":"List of legitimate parent processes expected to spawn PowerShell or scripting engines."}],"live":true,"detection_strategies":["DET0568"],"techniques":["T1674"]},{"id":"AN1568","stix_id":"x-mitre-analytic--b61673d6-244f-4888-9370-1a3ef391a6c2","name":"Analytic 1568","description":"Detects USB HID device enumeration under `/sys/bus/usb/devices/` and rapid keystroke injection resulting in command execution such as bash or Python scripts launched without interactive user activity.","url":"https://attack.mitre.org/detectionstrategies/DET0568#AN1568","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: parent process is usb/hid device handler, child process bash/python invoked","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"New HID device enumeration with type 'keyboard' followed by immediate input injection","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"USBVendorIDs","description":"Track suspicious or unapproved USB vendor/product IDs."},{"field":"ScriptExecutionThreshold","description":"Time threshold for script execution after HID injection, e.g., less than 10 seconds."}],"live":true,"detection_strategies":["DET0568"],"techniques":["T1674"]},{"id":"AN1569","stix_id":"x-mitre-analytic--4b47697b-ff9b-4af7-a079-d34210cebdab","name":"Analytic 1569","description":"Detects abnormal HID device enumeration via I/O Registry (ioreg -p IOUSB) and keystroke injection targeting AppleScript, osascript, or PowerShell equivalents. Defender correlates new USB device connections with rapid script execution.","url":"https://attack.mitre.org/detectionstrategies/DET0568#AN1569","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"New IOUSB keyboard/HID device enumerated with suspicious attributes","data_component":"DC0042","data_component_name":"Drive Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"osascript, AppleScript, or Python execution triggered immediately after HID connection","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AllowedAppleScripts","description":"Whitelist of AppleScripts expected in the environment, to minimize false positives."},{"field":"TimeWindow","description":"Timeframe between HID injection and script execution considered suspicious."}],"live":true,"detection_strategies":["DET0568"],"techniques":["T1674"]}],"live":true,"version":"1.0","techniques":["T1674"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}