πŸ”„ Topic

I completed a removable-media risk exercise built around a found USB drive. The obvious danger is plugging in an unknown device and executing malware. The less obvious lesson was that the files already on the drive can be enough to help an attacker plan a convincing social-engineering attack.


🎯 Goal

Practice analyzing a found removable device without interacting with it, separate the data-exposure risk from the malware risk, and recommend controls that address both.


πŸ›  What I Did

The completed exercise described a removable drive containing a mix of personal material and work-related documents, including information that could reveal staff names, roles, routines, and organizational details.

I analyzed two separate risk paths:

  • Information exposure: personal and work information on the same device can reveal details that support impersonation, phishing, or pretexting.
  • Device-borne malware: connecting an unknown drive can introduce ransomware, spyware, keyloggers, or a backdoor.

The important point is that neither path requires the other. A drive can be dangerous even if it contains no executable malware, because the information on it can be turned into a much more believable social-engineering lure. Likewise, a device can carry malware even if its filenames look harmless.


πŸ”— Key Cybersecurity Connections

This exercise connected several security ideas I have studied separately:

  • asset classification: personal and sensitive work data should not be casually mixed on unprotected removable media
  • social engineering: names, schedules, role details, and personal context help an attacker create a plausible pretext
  • defense in depth: user reporting, technical device control, encryption, and endpoint protection each cover different failure paths
  • least privilege: removable-media access should be enabled only where there is a real business need

The safest response to a found device is not curiosity. It is containment and reporting. A security team needs a route for employees to hand over suspicious media without anyone feeling that plugging it in is the fastest way to find out what it contains.


πŸ” Investigation Questions

  • Was an unknown device connected, and to which endpoint?
  • Does the device contain business data, personal data, or both?
  • Could visible names, schedules, or documents support a phishing or impersonation attempt?
  • Are removable-media controls enforced, or only stated in policy?
  • Is automatic execution disabled and are approved devices scanned?
  • Does the organization have a safe reporting and analysis process that keeps the device away from ordinary workstations?

🚨 Detection Opportunities

Useful signals include:

  • a new removable-storage device attached to an endpoint
  • executable files or suspicious shortcuts launched from removable media
  • unexpected process creation shortly after a device connection
  • sensitive documents copied to removable storage
  • large outbound transfers following removable-media activity
  • repeated failed attempts to mount blocked devices

Example triage note:

alert=unknown_removable_device_connected
endpoint=workstation-asset-id
user=assigned-user
immediate_action=contain_and_preserve_evidence
do_not_do=open_or_execute_files_on_the_workstation
follow_up=review_endpoint_and_device-control_telemetry

🧭 MITRE ATT&CK Techniques

Possible mappings when the corresponding behavior is actually observed:

  • T1091 β€” Replication Through Removable Media
  • T1204 β€” User Execution
  • T1566 β€” Phishing, where exposed context is used to make a lure convincing

The worksheet itself was an analytical exercise; it did not demonstrate that any of these techniques occurred.


πŸ—Ί Visual Investigation Diagram

Found USB device
    ↓
Do not connect it to a normal workstation
    ↓
Report and preserve it for approved handling
    ↓
Analyze two risks in parallel
    β”œβ”€β”€ data on the device β†’ social-engineering context
    └── device connection β†’ malware / unauthorized execution risk
    ↓
Apply policy, user training, device control, scanning, and encryption

⚠ Challenges

The challenge was not assuming that the threat starts only when someone plugs the device in. The data itself can expose a person or an organization before any malware executes. That made separating business data from personal files feel like a security boundary, not just tidiness.


πŸ“š What I Learned

I learned to treat removable media as two linked but distinct attack surfaces: the content can enable manipulation, and the hardware connection can enable malicious code. A useful analysis has to account for both.


➑ Next Steps

  • Review how endpoint tools record removable-media events
  • Practice writing a safe first-response checklist for a found device
  • Study how device-control policies can allow approved encrypted media while blocking unknown devices
  • Connect this scenario to phishing-pretext analysis and security-awareness training

🧠 Reflection

The exercise made a simple rule more meaningful: do not plug in unknown USB drives. The reason is not only β€œit might have a virus.” It can also be a container for information that makes the next attack much more personal and much more likely to work.


🧩 Lessons Learned

What worked

Separating the information risk from the device-execution risk before deciding on controls.

What could fail

Treating a found drive as harmless because it appears to contain ordinary photos or documents.

Takeaway

Do not connect unknown removable media. Preserve it, report it, and use layered controls to protect against both exposed information and malicious execution.


πŸ“ˆ Skill Progression Context

This strengthens my cybersecurity foundation because it combines threat modeling, social-engineering awareness, endpoint security, data classification, and incident reporting in one small but realistic scenario.


πŸ˜„ TL;DR

A found USB drive can attack through its files before it attacks through its code: report it, do not plug it in, and protect both the device and the information it carries.