Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

USB Device History Auditing with Nessus

Nessus plugin #35730 can perform an audit of Windows computers to obtain a list of all USB devices that may have been connected to it at one point in time. This plugin compliments plugin #24274 which utilizes a WMI query to list all currently installed USB devices.

Why is this important?

The media is full of news stories about how USB drives are contributing to the data loss problem. Searching for “usb data loss” at Google returned 744,000 hits. Similar stories are located at the DataLossDB project.

Knowing that a computer has had one or more USB devices attached to it and what they were is an excellent piece of information. If you can audit this information ahead of time, your organization can recognize trends and product usage on mobile devices and “thumb drives” that could be damaging. For example, you may allow the use of iPhone or MP3 devices in your offices, but connecting them to a corporate laptop via USB may be against policy.

If there is a form of data loss, knowing the exact types of devices that were attached to a server or desktop may also be important. Knowing the specific manufacturer information can help an investigation understand what sort of physical device was involved in any potential data loss, and may help pinpoint who it belonged to.

Performing the Scan with Nessus

Plugin #35730 (Windows USB Device Usage Report) is located in the “Windows” plugin family. It is shown selected in a Nessus Client scan policy below:

1-plugin-selection

By default the plugin only reports the 'First used' times for USB devices found in the initial section of the log file (setupapi.log). If you would like to report on all USB devices that have been added to the system, you should enable the “Thorough Tests” option under the advanced tab as shown below:
 2-thorough-checks


Lastly, to perform this audit, your scan policy should have an administrator account and a password to audit the remote Window operating system. If you are only performing a credentialed USB audit, you should also disable all forms of port scanning (to speed up your scan).

Below is a report of a Windows XP Pro system that has had several USB devices used on it recently:

3-results  


Real-time Enterprise Monitoring

For large networks, Tenable offers the ability to report on this information with the Security Center and to also monitor USB device usage in real-time with the Log Correlation Engine.

Security Center customers can leverage plugin #35370 on larger networks by deploying multiple Nessus scanners and performing their USB audits in a rapid and agent-less manner. The results of the scan can be easily searched (as shown below) and also used to create dynamic asset lists of computer groups that leverage certain types of technologies such as BlackBerry and iPods.

4-sc3-audit

Log Correlation Engine customers also can monitor for USB usage in real time. Through the use of the Log Correlation Engine client for Windows platforms, local USB usage as well as those of remote Windows servers can be monitored for device inserts and removals as shown below:

5-usb-insert

For More Information

Previously, we’ve blogged several times about using Nessus to perform some sort of USB technology audit. The following blog entries will likely be of interest:

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Your Tenable Vulnerability Management trial also includes Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose Your Subscription Option:

Buy Now

Try Tenable Web App Scanning

Enjoy full access to our latest web application scanning offering designed for modern applications as part of the Tenable One Exposure Management platform. Safely scan your entire online portfolio for vulnerabilities with a high degree of accuracy without heavy manual effort or disruption to critical web applications. Sign up now.

Your Tenable Web App Scanning trial also includes Tenable Vulnerability Management and Tenable Lumin.

Buy Tenable Web App Scanning

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

5 FQDNs

$3,578

Buy Now

Try Tenable Lumin

Visualize and explore your exposure management, track risk reduction over time and benchmark against your peers with Tenable Lumin.

Your Tenable Lumin trial also includes Tenable Vulnerability Management and Tenable Web App Scanning.

Buy Tenable Lumin

Contact a Sales Representative to see how Tenable Lumin can help you gain insight across your entire organization and manage cyber risk.

Try Tenable Nessus Professional Free

FREE FOR 7 DAYS

Tenable Nessus is the most comprehensive vulnerability scanner on the market today.

NEW - Tenable Nessus Expert
Now Available

Nessus Expert adds even more features, including external attack surface scanning, and the ability to add domains and scan cloud infrastructure. Click here to Try Nessus Expert.

Fill out the form below to continue with a Nessus Pro Trial.

Buy Tenable Nessus Professional

Tenable Nessus is the most comprehensive vulnerability scanner on the market today. Tenable Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.

Buy a multi-year license and save. Add Advanced Support for access to phone, community and chat support 24 hours a day, 365 days a year.

Select Your License

Buy a multi-year license and save.

Add Support and Training

Try Tenable Nessus Expert Free

FREE FOR 7 DAYS

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Already have Tenable Nessus Professional?
Upgrade to Nessus Expert free for 7 days.

Buy Tenable Nessus Expert

Built for the modern attack surface, Nessus Expert enables you to see more and protect your organization from vulnerabilities from IT to the cloud.

Select Your License

Buy a multi-year license and save more.

Add Support and Training