Initial Access via Phishing: USB Drop and Malicious Peripheral
Incident response playbook for physical USB device drop attacks, malicious storage devices, and HID attacks.
Prepare
5 steps- Reporting channel
The channel for reporting a suspicious physical device to the security team must be documented.
- USB policy
Removable storage access must be restricted via Intune/GPO; USB HID (keyboard) restriction must be evaluated separately, as it bypasses USB storage blocking.
- Detection rules
Sysmon EID 1 (execution from a non-C drive) and PnP EID 20001/20003 (new device connected) must be forwarded to SIEM and rules must be in production.
- Physical security
SOC access authority to CCTV and physical access records must be documented; chain-of-custody procedure must be ready.
- Authority definition
Account suspension and endpoint isolation authority within the SOC must be defined and tested.