Compliance Node Overview
MITRE ATT&CK T1052 (Exfiltration Over Physical Medium) is an Enterprise Exfiltration technique. Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a physical medium or device introduced by a user. Such media could be an external hard drive, USB drive, cellular phone, MP3 player, or other removable storage and processing device. The physical medium or device could be used as the final exfiltration point or to hop between otherwise disconnected systems. ATT&CK documents 1 sub-technique: T1052.001 Exfiltration over USB. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1057 Data Loss Prevention, M1034 Limit Hardware Installation, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, AC-16, AC-20, AC-23, CA-07, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1052/
SHA-256 integrity: 767ea21370eb2fc6ba688ac0c1690bf496b5d35360033c422053db84fe11a38e
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1052: Exfiltration Over Physical Medium (https://attack.mitre.org/techniques/T1052/) with 1 sub-techniques
- MITRE ATT&CK Tactic TA0010: Exfiltration (https://attack.mitre.org/tactics/TA0010/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access