LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1025: Data from Removable Media

Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Some adversaries may also use Automated Collection on removable media.

EnterpriseT1025TechniqueObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Data from Removable Media matters because a compromised workstation can become a bridge to sensitive files stored on USB drives, optical media, or other connected removable storage. For executives and security leaders, the practical issue is not just malware on a device; it is whether the organization can prove that sensitive data on removable media is monitored, controlled, and investigated before it is exfiltrated, including in environments that rely on removable media for operational or air-gapped workflows.

Executive priority

Prioritize this technique where removable media is allowed, required for business operations, or used around sensitive data. The ATT&CK relationships include multiple espionage-focused groups and malware families, including examples designed for document theft and air-gapped collection, so leaders should ask whether removable media use is governed by policy, covered by DLP, visible to the SOC, and included in incident response playbooks. This is especially relevant to audit evidence for data handling, insider-risk adjacent controls, and operational resilience in environments where blocking all removable media is not practical.

Technical view

This is an enterprise collection technique on Linux, macOS, and Windows. ATT&CK does not provide official detection text, but it links DET0511, Detection of Data Access and Collection from Removable Media, and mitigation M1057, Data Loss Prevention. SOC and IR teams should validate whether endpoints can identify removable media connection and access, whether file collection from removable paths is visible, and whether interactive shells or common command functionality touching removable media are distinguishable from normal user activity. Relationship context is heavily Windows-oriented for listed software, but the technique platform scope is Linux, macOS, and Windows, so coverage should be checked across all three where present.

Likely telemetry

  • Removable media connection, mount, and dismount events on Linux, macOS, and Windows endpoints
  • File access, enumeration, read, copy, archive, or staging activity involving removable media paths or volumes
  • Process execution telemetry showing command shells or common utilities accessing removable media
  • Endpoint DLP or device-control events involving sensitive file types, PII, intellectual property, or financial data on removable media
  • Host-based alerts or logs from detection strategy DET0511 where implemented

Detection direction

  • Confirm whether DET0511-equivalent logic exists and is enabled for all supported operating systems in scope, not only Windows.
  • Tune detection around unusual volume access patterns, bulk file reads, collection of sensitive document types, or command-shell interaction with removable media, while accounting for legitimate business processes such as backups, field operations, maintenance, or data transfer workflows.
  • Correlate removable media activity with later collection, staging, or exfiltration indicators when available; this technique is collection prior to exfiltration, not proof of data loss by itself.
  • Validate that logs preserve enough context to identify the user, host, device or volume, process, file path, and data category where available.
  • Check blind spots around unmanaged endpoints, offline systems, air-gapped processes, temporary contractors, and environments where removable media is permitted but not centrally monitored.

Mitigation priorities

  • Start with policy and inventory: define where removable media is allowed, prohibited, or exception-based, especially around sensitive data and operational systems.
  • Implement Data Loss Prevention controls aligned to M1057 to identify, categorize, monitor, and control sensitive data movement involving removable media.
  • Where business permits, restrict or approve removable media use through endpoint controls and enforce least-privilege access to sensitive files.
  • Ensure SOC and IR teams receive usable removable media and DLP telemetry, including from systems that may be intermittently connected or operationally isolated.
  • Create response procedures for suspected removable media collection, including host triage, user and device scoping, sensitive-data review, and follow-on exfiltration investigation.
Additional notes and limits

ATT&CK classifies this as a collection technique, not an exfiltration technique. The relationship set includes APT28, Turla, Gamaredon Group, OilRig, and many software examples, several of which are described as espionage, document theft, removable-device propagation, or air-gap related. That makes the behavior strategically important for environments with sensitive documents or removable media workflows, but local telemetry is required to determine exposure or activity.

Official ATT&CK detection text is not provided for T1025. Detection and mitigation guidance here is derived from the official description, supported platforms, the DET0511 detection-strategy relationship, the M1057 Data Loss Prevention mitigation relationship, and listed group/software relationships. No claim is made that this activity is currently occurring, that any named actor targets a specific organization, or that any control guarantees detection or prevention.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Data from Removable Media

Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory, etc.) connected to the compromised system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Some adversaries may also use Automated Collection on removable media.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
f08d07416d4d2576...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.