Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR045
  • Created: 19th July 2026
  • Updated: 19th July 2026
  • MITRE ATT&CK®: T1200
  • Contributor: The ITM Team

Unauthorized Hardware Introduction

A subject introduces, connects, installs, or positions unauthorized hardware within an organizational environment to establish a capability that may support a later infringement.

 

The hardware may provide network access, input capture, command execution, communications, surveillance, remote connectivity, or direct interaction with organizational systems. Examples include rogue network devices, hardware keyloggers, malicious peripheral devices, modified cables, portable computing devices, network taps, and embedded hardware implants.

 

Investigators should assess the device’s function, connection method, placement, ownership, configuration, communication activity, and the subject’s legitimate requirement to possess or deploy it. Particular attention should be given to hardware connected to sensitive systems, concealed from routine inspection, configured to communicate externally, or introduced outside approved procurement, asset management, and change control processes.