preventions
- ID: PV084
- Created: 10th March 2026
- Updated: 10th March 2026
- Contributor: Leonardo Segura
Physical Port Security for Workstations
Restrict physical access to USB and display ports on corporate workstations to prevent unauthorized hardware from being connected to the system.
Hardware-based remote access devices such as IP-KVM platforms require direct connection to the endpoint’s USB ports and video outputs in order to capture display output and inject keyboard or mouse input. If these physical interfaces are accessible, a subject may attach hardware capable of maintaining covert remote interaction with the system.
Implementing physical controls that limit access to these interfaces can significantly reduce the risk of unauthorized hardware devices being deployed on corporate endpoints.
Prevention Measures
- Disable unused USB ports through BIOS/UEFI configuration or endpoint management policies where operationally feasible.
- Use physical USB port blockers or locking port covers on systems deployed in shared offices, open workspaces, or other environments where unauthorized access to workstation ports is possible.
- Secure display interfaces such as HDMI or DisplayPort connections using cable management or port protection mechanisms to prevent insertion of intermediary capture devices.
- Establish workstation hardware inspection procedures during IT support visits, security audits, or equipment refresh cycles to identify unauthorized devices connected between system components.
- Maintain workstation configurations where peripheral cabling is visible and auditable, making it easier for support staff or security personnel to detect unfamiliar hardware devices attached to endpoints.
- Apply enhanced physical security measures to high-risk systems, including administrative workstations, developer environments, and systems that access sensitive or regulated data.
Sections
| ID | Name | Description |
|---|---|---|
| PR036 | Hardware-Based Remote Access (IP-KVM) | A subject deploys a hardware-based remote access device, typically an IP-KVM (Keyboard, Video, Mouse over IP) system, to remotely interact with a workstation or server through its physical interfaces.
These devices connect directly to the system’s video output (HDMI or DisplayPort) and USB ports, capturing the display signal while injecting keyboard and mouse input remotely. The device presents itself to the operating system as standard USB Human Interface Devices (HID), such as a generic keyboard and mouse, allowing the subject to interact with the system as though physically present at the console.
Because the interaction occurs through physical interface emulation rather than installed software, activity generated through the device appears as local console input to the operating system. This can bypass controls designed to detect or restrict software-based remote access tools such as Remote Desktop Protocol (RDP) or third-party remote administration platforms.
Many IP-KVM devices provide independent network connectivity, including Ethernet, Wi-Fi, or cellular access, allowing the subject to maintain remote interaction with the system through an external management interface. When used in this manner, the remote session may not traverse corporate remote access infrastructure or generate conventional remote access/network logs.
While these devices have legitimate uses in system administration, hardware labs, and data center environments, a subject may deploy them covertly to maintain persistent remote access to a system without installing software or triggering typical remote access monitoring or network controls.
Within the Insider Threat Matrix, this behavior represents preparatory activity, as it establishes a covert remote control capability that may later enable unauthorized access, data exfiltration, or system manipulation. |
| IF034 | Exfiltration via Automated Transcription | Exfiltration via automated transcription refers to the capture and conversion of spoken information into structured, persistent data through the use of transcription technologies, including AI-enabled note-taking tools, meeting assistants, and speech-to-text systems.
Unlike traditional media capture techniques, this behavior does not merely reproduce information, it transforms ephemeral verbal communication into searchable, shareable, and analyzable content. This significantly increases the utility and scalability of exfiltrated data, enabling subjects to accumulate large volumes of sensitive information over time with minimal manual effort.
This technique may occur using external tools operating outside organizational control or through misuse of approved or embedded transcription capabilities within enterprise platforms. As a result, it spans both out-of-band and in-band exfiltration paths, making it distinct from media capture behaviors.
In addition to software-based transcription tools, subjects may leverage dedicated or repurposed hardware to capture audio streams for later transcription or processing. This includes the use of intermediary devices capable of intercepting microphone input or headphone output, such as inline audio capture adapters, modified peripherals, or secondary recording devices connected to audio interfaces.
These methods enable the subject to capture high-quality audio directly from system inputs or outputs without relying on visible applications or introducing detectable software artifacts. In such cases, audio may be recorded covertly and later processed through transcription tools outside the organizational environment, further separating the point of capture from the point of transformation and exfiltration.
Exfiltration via automated transcription is particularly effective in environments where sensitive information is frequently communicated verbally, including strategic discussions, incident response, legal proceedings, and technical collaboration. The presence of this behavior may indicate deliberate collection of high-value conversational intelligence, especially where transcription outputs are retained, aggregated, or transferred beyond approved boundaries.
From an investigative perspective, this technique introduces a shift from event-based capture to continuous collection, where subjects build structured datasets over time. Detection therefore relies on identifying tool usage, data flows, and the presence of generated artifacts, rather than isolated capture events. |
| PR045 | Unauthorized Hardware Introduction | A subject introduces, connects, installs, or positions unauthorized hardware within an organizational environment to establish a capability that may support a later infringement.
The hardware may provide network access, input capture, command execution, communications, surveillance, remote connectivity, or direct interaction with organizational systems. Examples include rogue network devices, hardware keyloggers, malicious peripheral devices, modified cables, portable computing devices, network taps, and embedded hardware implants.
Investigators should assess the device’s function, connection method, placement, ownership, configuration, communication activity, and the subject’s legitimate requirement to possess or deploy it. Particular attention should be given to hardware connected to sensitive systems, concealed from routine inspection, configured to communicate externally, or introduced outside approved procurement, asset management, and change control processes. |
| PR040.003 | Testing Endpoint and Application Controls | A subject performs a limited action on an organizational endpoint to determine whether software restrictions, endpoint security controls, browser management, device controls, or application policies prevent or report the behavior.
The subject may install a low-impact unauthorized application, add a browser extension, execute a portable utility, alter a minor endpoint setting, or attempt to run software from an unusual location. They may also connect a removable device or use a test script to establish whether application allowlisting, Endpoint Detection and Response (EDR), antivirus, mobile device management, or device-control policies are active.
The test may be designed to resemble ordinary experimentation or troubleshooting. Investigators should consider whether the subject subsequently used the same installation method, application type, device, or control weakness to support data collection, persistence, circumvention, or another infringement. |