Limit Hardware Installation

Block users or groups from installing or using unapproved hardware on systems, including USB devices.

ID: M1034
Version: 1.0
Created: 11 June 2019
Last Modified: 09 June 2020

Techniques Addressed by Mitigation

Domain ID Name Use
Enterprise T1200 硬件附加

Block unknown devices and accessories by endpoint security configuration and monitoring agent.

Enterprise T1091 通过可移动媒体复制

Limit the use of USB devices and removable media within a network.

Enterprise T1052 通过物理介质渗出

Limit the use of USB devices and removable media within a network.

.001 Exfiltration over USB

Limit the use of USB devices and removable media within a network.