Skip to main content

yara l rule to detect data exfiltered to external driive

  • May 30, 2025
  • 1 reply
  • 25 views

NASEEF
Forum|alt.badge.img+8

Hello everyone 

Looking for guidance on detecting potential data exfiltration to external (USB/removable) drives. Has anyone built a YARA rule for identifying such activity

Open to examples or best practices for monitoring file transfers to removable media.

thanks in advance

1 reply

AbdElHafez
Staff
Forum|alt.badge.img+12
  • Staff
  • June 2, 2025

You will need to enable audit logging for removable media in GPO, or collect the events from a DLP.
There are some good starter examples in MITRE detections page ; https://attack.mitre.org/techniques/T1052/001/