Hardware Additions
Description
Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. [Replication Through Removable Media](https://attack.mitre.org/techniques/T1091)), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused. While public references of usage by threat actors are scarce, many red teams/penetration testers leverage hardware additions for initial access. Commercial and open source products can be leveraged with capabilities such as passive network tapping, network traffic modification (i.e. [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)), keystroke injection, kernel memory reading via DMA, addition of new wireless access points to an existing network, and others.(Citation: Ossmann Star Feb 2011)(Citation: Aleks Weapons Nov 2015)(Citation: Frisk DMA August 2016)(Citation: McMillan Pwn March 2012)
Mapped SPARTA techniques
3 techniques
Docking a hostile/adversary-controlled vehicle to the target spacecraft (OSAM context) is the orbital equivalent of T1200 'Hardware Additions' — physically introducing attacker hardware into the target system as the initial-access vector; cross-domain moderate because MITRE's typical example is USB/network-cable insertion.
Hostile grappling to the target spacecraft (mechanical attachment without OSAM cooperation) is the cross-domain orbital instance of T1200 'Hardware Additions'; the activity of physically attaching attacker hardware to gain access maps directly even though the medium is orbital rather than enterprise.
Auxiliary-device compromise also covers introduction of attacker-supplied hardware (rogue dongles, tampered cables, modified diagnostic boxes); T1200 'Hardware Additions' covers the physical-device-introduction aspect, complementary to T1091's removable-media path.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Countered by 2 in MITRE D3FEND (Defensive Techniques)
Cite as SafeMode Space, mitre-attack-enterprise T1200.