Detect Replication Through Removable Media in Splunk
Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system. This technique serves dual purposes: Initial Access (introducing malware into isolated or air-gapped environments) and Lateral Movement (propagating between networked systems via USB). Common implementations include creating autorun.inf files that auto-execute malware on media insertion, copying malicious executables to the drive root disguised as legitimate files, and creating LNK shortcut files that silently execute hidden payloads. Notable threat actors include Stuxnet (targeting air-gapped ICS/SCADA networks via CVE-2010-2568 LNK vulnerability), Flame (modular USB infection framework), Gamaredon Group (LNK files on all removable and network drives via UserAssist persistence), Mustang Panda and APT30 (customized PlugX USB variants), Raspberry Robin (worm spread via infected USB media), HIUPAN (periodic drive polling for propagation), and Aoqin Dragon (removable device dropper for breaching secure network environments).
MITRE ATT&CK
- Tactic
- Lateral Movement Initial Access
- Canonical reference
- https://attack.mitre.org/techniques/T1091/
SPL Detection Query
index=wineventlog sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" (EventCode=1 OR EventCode=11)
| eval target_path=case(EventCode="11", TargetFilename, EventCode="1", Image, true(), null())
| where isnotnull(target_path)
| eval drive_letter=upper(substr(target_path, 1, 1))
| where drive_letter!="C"
| where match(target_path, "(?i)^[A-Z]:\\\\")
| eval is_autorun=if(match(lower(target_path), "autorun\\.inf$"), 1, 0)
| eval is_executable=if(match(lower(target_path), "\\.(exe|dll|bat|cmd|vbs|js|lnk|hta|ps1|scr|pif|com)$"), 1, 0)
| eval path_depth=len(target_path) - len(replace(target_path, "\\\\", ""))
| eval is_root_level=if(path_depth <= 2, 1, 0)
| eval signal=case(
EventCode="11" AND is_autorun=1, "AutorunInfCreated",
EventCode="11" AND is_executable=1 AND is_root_level=1, "ExecutableAtDriveRoot",
EventCode="11" AND is_executable=1, "ExecutableOnRemovableMedia",
EventCode="1", "ProcessFromRemovableMedia",
true(), null()
)
| where isnotnull(signal)
| eval risk_score=case(
signal="AutorunInfCreated", 90,
signal="ProcessFromRemovableMedia", 88,
signal="ExecutableAtDriveRoot", 85,
signal="ExecutableOnRemovableMedia", 65,
true(), 50
)
| table _time, host, User, EventCode, signal, risk_score, target_path, drive_letter,
is_autorun, is_executable, is_root_level, ParentImage, ParentCommandLine
| sort - risk_score - _time Multi-signal SPL detection for T1091 using Sysmon Event ID 1 (Process Create) and Event ID 11 (File Create). Extracts the target path from either the Image field (EventCode=1) or TargetFilename field (EventCode=11), then filters for non-C: drive activity using drive letter extraction and regex matching. UNC network share paths are implicitly excluded by the drive letter pattern match. Classifies events into four signal types: AutorunInfCreated, ExecutableAtDriveRoot, ExecutableOnRemovableMedia, and ProcessFromRemovableMedia. Path depth calculation (backslash count) determines whether a file is at the drive root (depth 2 = single backslash after drive letter, e.g., D:\file.exe). Risk scores enable analyst prioritization.
Data Sources
Required Sourcetypes
False Positives & Tuning
- Software installations from USB drives — legitimate installers (msiexec.exe, setup.exe) writing executables to non-C: drive paths during product installation
- Backup software writing executable content as part of full system backups to external USB hard drives on configured backup schedules
- IT administrators manually copying tools or OS deployment packages to removable media for endpoint remediation tasks
- Portable application suites (PortableApps, U3 platform) that legitimately run executables directly from USB drive paths
- Multi-drive workstations with secondary internal drives assigned D:, E:, or higher drive letters — requires environment-specific tuning to exclude known fixed drive paths
- Media production or development workflows using large external drives to store executables or toolchains accessed from non-C: paths
Other platforms for T1091
Testing Methodology
Validate this detection against 5 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Create autorun.inf on Non-System Drive
Expected signal: Sysmon Event ID 11 (File Create): TargetFilename=D:\autorun.inf, Image=cmd.exe. DeviceFileEvents in MDE: FileName=autorun.inf, FolderPath=D:\, ActionType=FileCreated, InitiatingProcessFileName=cmd.exe.
- Test 2Copy Executable to Removable Drive Root (PlugX/HIUPAN Pattern)
Expected signal: Sysmon Event ID 11 (File Create): TargetFilename=D:\system_update.exe, Image=cmd.exe, MD5 matches cmd.exe hash. DeviceFileEvents in MDE: FileName=system_update.exe, FolderPath=D:\, ActionType=FileCreated, SHA256 matches cmd.exe.
- Test 3Create Malicious LNK Shortcut on Removable Drive (Gamaredon Technique)
Expected signal: Sysmon Event ID 11 (File Create): TargetFilename=D:\Documents.lnk, Image=powershell.exe. DeviceFileEvents in MDE: FileName=Documents.lnk, FolderPath=D:\, ActionType=FileCreated, InitiatingProcessFileName=powershell.exe. WindowStyle=7 (minimized/hidden window) indicates deliberate concealment.
- Test 4Execute Process Directly from Removable Drive
Expected signal: Sysmon Event ID 1 (Process Create): Image=D:\usb_payload.exe, CommandLine=D:\usb_payload.exe /C whoami, ParentImage=cmd.exe. DeviceProcessEvents in MDE: FileName=usb_payload.exe, FolderPath=D:\, ProcessCommandLine contains 'whoami'. Preceded by Sysmon Event ID 11 for the file copy.
- Test 5Enumerate Removable Drives via WMI (USB Worm Reconnaissance)
Expected signal: Sysmon Event ID 1 (Process Create): Image=powershell.exe, CommandLine contains 'Win32_LogicalDisk' and 'DriveType'. DeviceProcessEvents in MDE: FileName=powershell.exe, ProcessCommandLine contains WMI query. WMI Activity log (Microsoft-Windows-WMI-Activity/Operational Event ID 5857/5858) may record the Win32_LogicalDisk query.
References (10)
- https://attack.mitre.org/techniques/T1091/
- https://securelist.com/the-flame-malware/73765/
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-usb-threat-ukraine
- https://www.threatexpert.com/report.aspx?md5=4c48f0dc5c55e26d5b68dfafe2e54b31
- https://www.trendmicro.com/en_us/research/22/f/raspberry-robin-worming-its-way-through-networks.html
- https://www.sentinelone.com/labs/aoqin-dragon-newly-discovered-chinese-linked-apt-has-been-quietly-spying-on-organizations-for-10-years/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1091/T1091.md
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/control-usb-devices-using-intune
- https://learn.microsoft.com/en-us/defender-endpoint/advanced-hunting-devicefileevents-table
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4663
Unlock Pro Content
Get the full detection package for T1091 including response playbook, investigation guide, and atomic red team tests.