Files
blue-team-tools/rules/windows/builtin/security/win_security_external_device.yml
T
2022-10-14 08:53:50 +02:00

26 lines
678 B
YAML

title: External Disk Drive Or USB Storage Device
id: f69a87ea-955e-4fb4-adb2-bb9fd6685632
status: test
description: Detects external diskdrives or plugged in USB devices , EventID 6416 on windows 10 or later
author: Keith Wright
date: 2019/11/20
modified: 2022/10/09
tags:
- attack.t1091
- attack.t1200
- attack.lateral_movement
- attack.initial_access
logsource:
product: windows
service: security
detection:
selection:
EventID: 6416
ClassName: 'DiskDrive'
selection2:
DeviceDescription: 'USB Mass Storage Device'
condition: selection or selection2
falsepositives:
- Legitimate administrative activity
level: low