{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/device-control/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["endpoint","device-control","threat-detection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief concerns a detection capability for monitoring removable media usage across enterprise endpoints. Adversaries frequently leverage USB storage devices to introduce malware, achieve initial access, facilitate lateral movement, or exfiltrate sensitive data by exploiting the plug-and-play nature of modern operating systems. The Elastic detection rule tracks device mount events, specifically monitoring for new combinations of device serial numbers and host identifiers. By identifying devices that have not been previously seen on a specific host within a defined history window, security teams can focus investigations on potentially unauthorized hardware usage. While the presence of a new USB device is not inherently malicious, it serves as a critical indicator for identifying abnormal activity in environments where removable media usage should be tightly controlled.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of removable media can lead to the introduction of malicious payloads into isolated environments, the theft of sensitive internal data, or the facilitation of lateral movement across network segments. Unauthorized use of USB drives poses significant risks to data integrity and organizational security policy compliance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of device control policies to restrict unauthorized hardware.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided logic to track new device serial numbers and host identifiers to your SIEM.\u003c/li\u003e\n\u003cli\u003eEstablish a process to inventory and register approved company-issued USB devices to reduce noise.\u003c/li\u003e\n\u003cli\u003eReview file access and transfer logs immediately following a 'new device' alert to assess if data exfiltration is occurring.\u003c/li\u003e\n\u003cli\u003eIf a device is identified as malicious, utilize Device Control policies to block the specific serial number across the environment.\u003c/li\u003e\n\u003cli\u003eIsolate hosts where unauthorized devices were detected to prevent potential lateral movement or malware propagation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:19:03Z","date_published":"2026-09-18T19:19:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-new-usb-mounted/","summary":"Detection rule identifies first-time seen USB storage devices mounted on Windows and macOS endpoints to help analysts monitor for potential initial access, lateral movement, or data exfiltration.","title":"Detection of New USB Storage Device Mounting","url":"https://feed.craftedsignal.io/briefs/2026-09-new-usb-mounted/"}],"language":"en","title":"CraftedSignal Threat Feed - Device-Control","version":"https://jsonfeed.org/version/1.1"}