Meta tags:
Headings (most frequently used words):
communication, through, removable, media, procedure, examples, mitigations, detection, strategy, references,
Text of the page (most frequently used words):
the (14), media (12), and (11), #removable (11), att (10), all (10), enterprise (7), techniques (6), retrieved (6), system (6), 2015 (5), are (5), ics (5), mobile (5), none (5), through (5), mitre (4), data (4), detection (4), microsoft (4), 2016 (4), october (4), with (4), apt28 (4), file (4), usb (4), communication (4), commands (4), version (4), cti (3), mitigations (3), defenses (3), sub (3), disable (3), into (3), volume (3), air (3), gapped (3), that (3), access (3), host (3), files (3), description (3), for (3), second (3), victim (3), inserted (3), using (3), command (3), from (3), connected (3), compromised (3), 2026 (2), corporation (2), policy (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), august (2), april (2), windows (2), sednit (2), part (2), november (2), espionage (2), operations (2), networks (2), 2017 (2), followed (2), same (2), execution (2), written (2), executed (2), relay (2), via (2), analytic (2), name (2), drive (2), first (2), when (2), usbstealer (2), transfer (2), chopstick (2), control (2), t1092 (2), can (2), disconnected (2), would (2), internet (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, terms, use, contact, reset, filters, 2007, https, technet, com, library, cc771759, aspx, how, autorun, functionality, eset, route, observing, comings, goings, fireeye, window, russia, cyber, anthe, security, intelligence, report, december, calvet, 2014, group, attacking, january, references, correlates, mounts, disk, arbitration, events, shortly, after, insert, an0249, write, mount, directories, run, another, an0248, behavioral, sequence, where, mounted, updated, subsequently, read, separate, suggesting, an0247, cross, det0090, strategy, disallow, restrict, organizational, level, they, not, required, business, operating, configuration, m1028, autoruns, unnecessary, remove, feature, program, m1042, mitigation, drops, onto, s0136, operation, involved, modules, copy, itself, machines, sticks, traffic, s0023, uses, tool, captures, information, computers, infected, transfers, network, computer, g0007, procedure, examples, live, permalink, 2025, last, modified, may, created, linux, macos, platforms, tactic, adversaries, perform, between, hosts, potentially, both, systems, need, likelihood, was, lateral, movement, relayed, which, adversary, has, direct, replication, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
communication through removable media technique t1092 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise communication through removable media communication through removable media adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system 1 both systems would need to be compromised with the likelihood that an internet connected system was compromised first and the second through lateral movement by replication through removable media commands and files would be relayed from the disconnected system to the internet connected system to which the adversary has direct access id t1092 sub techniques no sub techniques ⓘ tactic command and control ⓘ platforms linux windows macos version 1 0 created 31 may 2017 last modified 24 october 2025 version permalink live version procedure examples id name description g0007 apt28 apt28 uses a tool that captures information from air gapped computers via an infected usb and transfers it to network connected computer when the usb is inserted 2 s0023 chopstick part of apt28 s operation involved using chopstick modules to copy itself to air gapped machines using files written to usb sticks to transfer data and command traffic 3 4 2 s0136 usbstealer usbstealer drops commands for a second victim onto a removable media drive inserted into the first victim and commands are executed when the drive is inserted into the second victim 1 mitigations id mitigation description m1042 disable or remove feature or program disable autoruns if it is unnecessary 5 m1028 operating system configuration disallow or restrict removable media at an organizational policy level if they are not required for business operations 6 detection strategy id name analytic id analytic description det0090 cross host c2 via removable media relay an0247 behavioral sequence where removable media is mounted files are written updated and subsequently read executed on a separate host suggesting removable media relay communication an0248 detection of file write access to usb mount directories e g media run media followed by same file access or execution on another host an0249 correlates removable volume mounts disk arbitration with file i o events on that volume followed by same file execution shortly after insert references calvet j 2014 november 11 sednit espionage group attacking air gapped networks retrieved january 4 2017 anthe c et al 2015 october 19 microsoft security intelligence report volume 19 retrieved december 23 2015 fireeye 2015 apt28 a window into russia s cyber espionage operations retrieved august 19 2015 eset 2016 october en route with sednit part 2 observing the comings and goings retrieved november 21 2016 microsoft n d how to disable the autorun functionality in windows retrieved april 20 2016 microsoft 2007 august 31 https technet microsoft com en us library cc771759 v ws 10 aspx retrieved april 20 2016 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|