Skip to content

Latest commit

 

History

History
15 lines (10 loc) · 652 Bytes

Peripheral_device_discovery.md

File metadata and controls

15 lines (10 loc) · 652 Bytes

Peripheral Device Discovery

MITRE ATT&CK technique T1120

Tactic: Discovery

Platform: Windows

Deception Techniques

  • Create emulated or virtual USB devices and monitor access to them (e.g. using Windows Removable Storage Auditing)

Useful Tools

  • Ghost USB Honeypot - It emulates a USB storage device to detect malwares that use such devices for propagation. Ghost supports Windows XP 32 bit and Windows 7 32 bit.
  • USB/IP project
  • Honeyprint - Printer honeypot PoC