T1052.001 — Exfiltration over USB
T1052.001: Exfiltration over USB
MITRE ATT&CK® Enterprise technique
| Tactics | Exfiltration |
| Platforms | Linux, Windows, macOS |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1052 |
Description
Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a USB device introduced by a user. The USB device could be used as the final exfiltration point or to hop between otherwise disconnected systems.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1052/001
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/