Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0301 — Removable Media Execution Chain Detection via File and Process Activity
DET0301

Removable Media Execution Chain Detection via File and Process Activity

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0841 Analytic 0841
Windows

Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.

WinEventLog:System EventCode=1006 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=1 WinEventLog:Microsoft-Windows-Windows Defender/Operational Suspicious file execution on removable media path
[DriveLetterMatch] Detect activity on mounted drives typically used by USB (e.g., E:, F:, G:). Tune based on enterprise usage.
[FileExecutionWindow] Set timing threshold for execution shortly after drive mount (e.g., < 5 minutes).
[ParentProcess] Restrict detection to suspicious process lineage like explorer.exe, powershell.exe, or unsigned binaries.
[FileEntropy] Use entropy thresholding to detect packed/obfuscated payloads dropped to removable media.

Detected Techniques

1

Details

MITRE ID
DET0301
STIX ID
x-mitre-detection-strategy--8225c396-cbf9-499a-b94d-bdc7a1f07458
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.