For the complete documentation index, see llms.txt. This page is also available as Markdown.

A user connected a new USB storage device to a host

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

ATT&CK Tactic

Collection (TA0009), Exfiltration (TA0010)

ATT&CK Technique

Data Staged (T1074), Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001)

Severity

Informational

Description

A user connected a new USB storage device that was not seen for this user and host in the last 30 days.

Attacker's Goals

The attacker may use a USB storage device connection for data exfiltration or data collection.

Investigative actions

Investigate the USB storage device-related process and file events to determine if it was used for legitimate purposes or malicious activity.

Was this helpful?