216.73.216.233

T1200: Hardware Additions

View on MITRE ATT&CK The MITRE Corporation · Published 18/04/2018 19:59 · Modified 27/03/2026 01:12

Essential information

MITRE technique ID
T1200
Confidence
100/100
Revoked
No
Published
18/04/2018 19:59
Modified
27/03/2026 01:12
Author / Source
The MITRE Corporation

Aliases

T1200

Platforms

windows macos linux

Description

Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. [Replication Through Removable Media](https://attack.mitre.org/techniques/T1091)), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused. While public references of usage by threat actors are scarce, many red teams/penetration testers leverage hardware additions for initial access. Commercial and open source products can be leveraged with capabilities such as passive network tapping, network traffic modification (i.e. [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)), keystroke injection, kernel memory reading via DMA, addition of new wireless access points to an existing network, and others.(Citation: Ossmann Star Feb 2011)(Citation: Aleks Weapons Nov 2015)(Citation: Frisk DMA August 2016)(Citation: McMillan Pwn March 2012)

Kill chain phases

Kill chainPhase
mitre-attack initial-access

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references