kevmap

TechniquesT1219.003 › AN0446

AN0446 Analytic 0446

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements.</p>
Detects
T1219.003 Remote Access Hardware
Part of
DET0159 Detect Remote Access via USB Hardware (TinyPilot, PiKVM)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SystemEventCode=2003DC0042 Drive Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
VendorIDDevice vendor strings may need tuning to include additional remote hardware sources.
SerialNumberSerial numbers for known implants can vary per campaign and may need expansion.
TimeWindowAdjust the detection window for peripheral enumeration based on environment and operating hours.