Hunt playbook
Unapproved USB / Removable Media
Identify removable media use on OT hosts, especially engineering and operator systems.
FoundationalT0847T0862
Hypothesis
Removable media may be used on OT hosts without going through the approved sanitisation process.
Why this hunt matters
Removable media remains a documented crossing point into otherwise isolated environments.
Scope
Assets: engineering-workstation, hmi, scada-server
Protocols:
Data sources required
- Windows device installation and PnP events
- Endpoint agent logs
- Kiosk/scanning station records
- Media control policy exceptions
Baseline needed first
- Media use only via a sanitisation kiosk, tied to a work order
Hunt steps
- 01Extract removable device insertion events per host for the period
- 02Filter out approved devices and known engineering media
- 03Correlate remaining events with work orders and kiosk scan records
- 04Review file executions or transfers shortly after insertion
Indicators of interest
- Insertion on an operator station
- New executables run after insertion
- Personal or unknown device identifiers
- Out-of-hours use
Triage
- Who was on shift?
- What files moved?
- Was the media scanned?
Likely false positives
- Vendor firmware updates
- Legitimate data extraction for reporting
- Keyboards and licence dongles enumerating as devices
Escalation
- Execution following insertion
- Engineering or safety host involved
Containment options
- Retain the media for analysis where possible
Validation
- Media control policy enforced technically
- Kiosk process used consistently
Why should I care?
Containment in OT is a joint decision. Isolating a device can be the safest action or the one that stops production — operations decides, security advises.