Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)

Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.

FreeReviewedSigma · Low · v2
Product
windows
Service
driver-framework
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-11-09
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows DriverFrameworks UserMode operational activity associated with USB device plug/unplug or related PnP/power management changes. Attackers commonly rely on removable media and peripheral connections to reach a system, so tracking these device lifecycle events can help identify unusual attachment activity. The detection relies on Microsoft-Windows-DriverFrameworks-UserMode/Operational events with Event IDs 2003, 2100, and 2102.

Related detections2 linkedT1200 — drag to rearrange
Windows Security Event 6423: Device Installation Blocked by Policy
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Pivot detection · T1200 · 2 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.