kevmap

TechniquesT1200 › AN0187

AN0187 Analytic 0187

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Chain: (1) unified logs report IOUSBHost/IOThunderbolt device arrival; (2) diskarbitrationd attaches a new volume; (3) optional: config profile manipulation or new network interface MAC obtains a lease. Correlate unifiedlogs (subsystems: IOUSBHost, IOKit, diskarbitrationd), FSEvents, and DHCP/Zeek.</p>
Detects
T1200 Hardware Additions
Part of
DET0069 Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogDevice attached|enumerated VID/PIDDC0038 Application Log Content
macos:unifiedlogmounted|appeared|DA: disk* attachedDC0042 Drive Creation
NSM:FlowMAC not in allow-list acquiring IP (DHCP)DC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ManagedUSBPolicyMDM profile expectations for external media and Thunderbolt mode; deviations alert.
KnownAppleAccessoriesVID/PID for corporate-issued docks/keyboards.