You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: First Seen USB device in use on Windows host
Description
This signal looks for a new removable USB device name being used by a host not seen since the baseline period. This activity by itself is not necessarily malicious, but can be indicative of potential lateral movement or initial access tactics. If the device name is unexpected and not authorized to be used in the environment, investigate the alert further and look for file creation events to the drive in question. The fields["EventData.DeviceDescription"] field contains the device name.
Additional Details
Detail
Value
Type
First Seen
Category
Lateral Movement
Apply Risk to Entities
device_hostname
Signal Name
First Seen USB device in use on Windows host: {{device_hostname}}
Summary Expression
A First Seen USB device found on {{device_hostname}}