A user connected a new USB storage device to a host
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Data Staged (T1074), Exfiltration Over Physical Medium: Exfiltration over USB (T1052.001)
Severity
Informational
Description
A user connected a new USB storage device that was not seen for this user and host in the last 30 days.
Attacker's Goals
The attacker may use a USB storage device connection for data exfiltration or data collection.
Investigative actions
Investigate the USB storage device-related process and file events to determine if it was used for legitimate purposes or malicious activity.
PreviousA user changed the Windows system time
NextA user connected a new USB storage device to multiple hosts
Was this helpful?
