Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1120
MITRE ATT&CK Technique

T1120: Peripheral Device Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.(Citation: Peripheral Discovery Linux)(Citation: Peripheral Discovery macOS) Peripheral devices could include auxiliary resources that support a variety of functionalities such as keyboards, printers, cameras, smart card readers, or removable storage. The information may be used to enhance their awareness of the system and network environment or may be used for further actions.

Tactics
Discovery
Platforms
Linux, macOS, Windows

▪Used by groups (9)

G0007APT28G0010TurlaG0020EquationG0047Gamaredon GroupG0049OilRigG0067APT37G0135BackdoorDiplomacyG0139TeamTNTG1017Volt Typhoon

▪Software using this technique (47)

S0013PlugXmalwareS0045ADVSTORESHELLmalwareS0062DustySkymalwareS0089BlackEnergymalwareS0098T9000malwareS0113PrikormkamalwareS0115CrimsonmalwareS0128BADNEWSmalwareS0136USBStealermalwareS0148RTMmalwareS0149MoonWindmalwareS0234BandookmalwareS0251ZebrocymalwareS0283jRATmalwareS0366WannaCrymalwareS0381FlawedAmmyymalwareS0385njRATmalwareS0409MachetemalwareS0438AttormalwareS0452USBferrymalwareS0454CadelspymalwareS0458RamsaymalwareS0467TajMahalmalwareS0481Ragnar LockermalwareS0538CrutchmalwareS0603StuxnetmalwareS0612WastedLockermalwareS0644ObliqueRATmalwareS0647TurianmalwareS0650QakBotmalwareS0673DarkWatchmanmalwareS0679FerociousmalwareS0686QuietSievemalwareS1026MongallmalwareS1027Heyoka BackdoormalwareS1044FunnyDreammalwareS1064SVCReadymalwareS1089SharpDiscomalwareS1090NightClubmalwareS1139INC RansomwaremalwareS1149CHIMNEYSWEEPmalwareS1150ROADSWEEPmalwareS1167AcidPourmalwareS1199LockBit 2.0malwareS1202LockBit 3.0malwareS1230HIUPANmalwareS9038DynoWipermalware

▪Reference

T1120on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.