Hardware Additions

T1200

Technique.View on attack.mitre.org

About this technique

Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. Replication Through Removable Media), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused.

While public references of usage by threat actors are scarce, many red teams/penetration testers leverage hardware additions for initial access. Commercial and open source products can be leveraged with capabilities such as passive network tapping, network traffic modification (i.e. Adversary-in-the-Middle), keystroke injection, kernel memory reading via DMA, addition of new wireless access points to an existing network, and others.

Detection rules13

Rules on DetectionCode tagged with T1200.

Sigma3

RuleLevelLog source
Device Installation Blockedmediumwindows / NULL
External Disk Drive Or USB Storage Device Was Recognized By The Systemlowwindows / NULL
USB Device Pluggedlowwindows / NULL

Splunk10

RuleTypeRiskData source
Detect ARP PoisoningTTPNULLCisco IOS Logs
Detect IPv6 Network Infrastructure ThreatsTTPNULLCisco IOS Logs
Detect Port Security ViolationTTPNULLCisco IOS Logs
Detect Rogue DHCP ServerTTPNULLCisco IOS Logs
Detect Traffic MirroringTTPNULLCisco IOS Logs
Linux Auditd Hardware Addition SwapoffAnomalyNULLLinux Auditd Execve
Linux Hardware Addition SwapOffAnomalyNULLSysmon for Linux EventID 1
Windows Process Executed From Removable MediaAnomalyNULLSysmon EventID 1 AND Sysmon EventID 13
Windows USBSTOR Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13
Windows WPDBusEnum Registry Key ModificationAnomalyNULLSysmon EventID 12, Sysmon EventID 13

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupDarkVishnya

DarkVishnya physically connected Bash Bunny, Raspberry Pi, netbooks, and inexpensive laptops to the target organization's environment to access the company’s local network.

References4

  1. Aleks Weapons Nov 2015 Open source
    Nick Aleks. (2015, November 7). Weapons of a Pentester - Understanding the virtual & physical tools used by white/black hat hackers. Retrieved March 30, 2018.
  2. Frisk DMA August 2016 Open source
    Ulf Frisk. (2016, August 5). Direct Memory Attack the Kernel. Retrieved March 30, 2018.
  3. McMillan Pwn March 2012 Open source
    Robert McMillan. (2012, March 3). The Pwn Plug is a little white box that can hack your network. Retrieved March 30, 2018.
  4. Ossmann Star Feb 2011 Open source
    Michael Ossmann. (2011, February 17). Throwing Star LAN Tap. Retrieved March 30, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.