T1025Techniquecollectionagent-callable

T1025Data from Removable Media

Platforms: Linux · macOS · Windows

ATT&CK version: 14.1

What it is

Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within [cmd](https://attack.mitre.org/software/S0106) may be used to gather information. Some adversaries may also use [Automated Collection](https://attack.mitre.org/techniques/T1119) on removable media.

ATT&CK tactics· 1

Collection

References

  1. https://attack.mitre.org/techniques/T1025
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.