Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition

Flags Windows Event ID 6416 entries where a DiskDrive/USB Mass Storage Device is detected as connected.

FreeReviewedSigma · Low · v2
Product
windows
Service
security
Author
Keith Wright (SigmaHQ), DRL 1.1
Published
2019-11-20
Updated
2026-07-31

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows Security audit events indicating that an external disk drive or a plugged-in USB mass storage device was recognized by the system. Attackers can use removable media to introduce tools or files for initial access or lateral movement, making device plug-in events a useful indicator of suspicious activity. It relies on Windows Security logs capturing EventID 6416 with DiskDrive class and DeviceDescription set to USB Mass Storage Device.

Related detections6 linkedT1091 — drag to rearrange
TinyLoader USB Propagation via Double-Extension Executables (via file_event)
Suspicious Process Execution From Recycle Bin Directory
Suspicious Removable Media Spread via My Pictures Executable (via process_creation)
Suspicious Ukraine-Themed LNK Lure Files Dropped (via file_event)
Windows Security Event 6423: Device Installation Blocked by Policy
Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Pivot detection · T1091 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.