ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1120×

9 examples

TechniqueUsed byProcedure example
T1120
Peripheral Device Discovery
GroupVolt Typhoon

Volt Typhoon has obtained victim's screen dimension and display device information.

T1120
Peripheral Device Discovery
GroupGamaredon Group

Gamaredon Group tools have contained an application to check performance of USB flash drives. Gamaredon Group has also used malware to scan for removable drives.

T1120
Peripheral Device Discovery
GroupTeamTNT

TeamTNT has searched for attached VGA devices using lspci.

T1120
Peripheral Device Discovery
GroupAPT37

APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.

T1120
Peripheral Device Discovery
GroupOilRig

OilRig has used tools to identify if a mouse is connected to a targeted system.

T1120
Peripheral Device Discovery
GroupTurla

Turla has used fsutil fsinfo drives to list connected drives.

T1120
Peripheral Device Discovery
GroupEquation

Equation has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware.

T1120
Peripheral Device Discovery
GroupBackdoorDiplomacy

BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives.

T1120
Peripheral Device Discovery
GroupAPT28

APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.