Exfiltration Over Physical Medium

Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive or ODB-II. In certain circumstances, such as an offline network compromise, exfiltration could occur via a physical medium or device introduced by a user. Such media could be an external hard drive, USB drive, cellular phone or other removable storage and processing device. The physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems.

ID: T2079
Sub-techniques:  No sub-techniques
Tactic: Exfiltration
Version: 1.0
Created: 03 December 2023
Last Modified: 03 December 2023
ATT&CK Reference:  T1052

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.