MITRE ATT&CK Enterprise
T1200

Hardware Additions

Description

Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting and distributing payloads via removable storage (i.e. [Replication Through Removable Media](https://attack.mitre.org/techniques/T1091)), more robust hardware additions can be used to introduce new functionalities and/or features into a system that can then be abused. While public references of usage by threat actors are scarce, many red teams/penetration testers leverage hardware additions for initial access. Commercial and open source products can be leveraged with capabilities such as passive network tapping, network traffic modification (i.e. [Adversary-in-the-Middle](https://attack.mitre.org/techniques/T1557)), keystroke injection, kernel memory reading via DMA, addition of new wireless access points to an existing network, and others.(Citation: Ossmann Star Feb 2011)(Citation: Aleks Weapons Nov 2015)(Citation: Frisk DMA August 2016)(Citation: McMillan Pwn March 2012)

Mapped SPARTA techniques

3 techniques

  • IA-0005.02Docked Vehicle / OSAMST0003
    addresses
    moderate

    Docking a hostile/adversary-controlled vehicle to the target spacecraft (OSAM context) is the orbital equivalent of T1200 'Hardware Additions' — physically introducing attacker hardware into the target system as the initial-access vector; cross-domain moderate because MITRE's typical example is USB/network-cable insertion.

  • IA-0005.03Proximity GrapplingST0003
    addresses
    moderate

    Hostile grappling to the target spacecraft (mechanical attachment without OSAM cooperation) is the cross-domain orbital instance of T1200 'Hardware Additions'; the activity of physically attaching attacker hardware to gain access maps directly even though the medium is orbital rather than enterprise.

  • IA-0011Auxiliary Device CompromiseST0003
    addresses
    moderate

    Auxiliary-device compromise also covers introduction of attacker-supplied hardware (rogue dongles, tampered cables, modified diagnostic boxes); T1200 'Hardware Additions' covers the physical-device-introduction aspect, complementary to T1091's removable-media path.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Countered by 2 in MITRE D3FEND (Defensive Techniques)

Cite as SafeMode Space, mitre-attack-enterprise T1200.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.