Techniques › T1120
T1120 Peripheral Device Discovery
discovery — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
2
Sigma rules tagged attack.t1120
0
KEV CVEs mapped here
<p>Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0491 Peripheral Device Enumeration via System Utilities and API Calls v1.0
AN1353 WindowsSuspicious enumeration of attached peripherals via WMI, PowerShell, or low-level API calls potentially chained with removable device interactions.Tunable:
CommandLineRegexTimeWindowUserContextAN1354 LinuxEnumeration of USB and other peripheral hardware via udevadm, lshw, or /sys or /proc interfaces in proximity to collection or mounting behavior.Tunable:ExecutableListUserContextAN1355 macOSExecution of system utilities like 'system_profiler' and 'ioreg' to enumerate hardware components or USB devices, particularly if followed by clipboard, file, or network activity.Tunable:BinaryListTimeWindow
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1120
Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
· 2022-03-29 (modified 2022-07-14) · logsource: product=windows category=process_creation · 63de06b9-a385-40b5-8b32-73f2b9ef84b6
Attackers may leverage fsutil to enumerated connected drives.
Author: frack113
· 2021-08-23 (modified 2022-12-25) · logsource: product=windows category=ps_script · b26647de-4feb-4283-af6b-6117661283c5
Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.