Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.
.claude/skills/cyberstrikeus-t1458-replication-through-removable-media/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | -22% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 6% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 69% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 12% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -41% | 0% |
Adversaries may move onto devices by exploiting or copying malware to devices connected via USB. In the case of Lateral Movement, adversaries may utilize the physical connection of a device to a compromised or malicious charging station or PC to bypass application store requirements and install malicious applications directly. In the case of Initial Access, adversaries may attempt to exploit the device via the connection to gain access to data stored on the device. Examples of this include:
Platforms: Android, iOS
Determine if the target mobile environment is susceptible to Replication Through Removable Media by examining the target platforms (Android, iOS).
Review whether mitigations for T1458 are in place. If defenses are absent or misconfigured, this technique may be exploitable.
Users should ensure bootloaders are locked to prevent arbitrary operating system code from being flashed onto the device.
iOS 11.4.1 and higher introduce USB Restricted Mode, which disables data access through the device's charging port under certain conditions (making the port only usable for power), likely preventing this technique from working.
Users should be advised not to use public charging stations or computers to charge their devices. Instead, users should be issued a charger acquired from a trustworthy source. Users should be advised not to click on device prompts to trust attached computers unless absolutely necessary.
Enterprise policies should prevent enabling USB debugging on Android devices unless specifically needed (e.g., if the device is used for application development).
Security updates often contain patches for vulnerabilities.
| Finding | Severity | Impact | | -------------------------------------------------------- | -------- | -------------- | | Replication Through Removable Media technique applicable | High | Initial Access |
| CWE ID | Title | | ------ | ------------------------- | | CWE-20 | Improper Input Validation |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | fail→pass | 19,579 | 9,954 | -49% | 1 | 1 | 0% | 2,262 | 1,757 | -22% | 0 | 0 | — |
case-01 | fail→pass | 20,609 | 21,263 | +3% | 1 | 1 | 0% | 3,187 | 3,367 | +6% | 0 | 0 | — |
case-02 | fail→pass | 31,650 | 37,453 | +18% | 1 | 1 | 0% | 3,548 | 6,008 | +69% | 0 | 0 | — |
case-03 | fail→pass | 37,063 | 41,239 | +11% | 1 | 1 | 0% | 5,273 | 5,917 | +12% | 0 | 0 | — |
case-04 | pass→pass | 20,194 | 9,713 | -52% | 1 | 1 | 0% | 1,723 | 1,714 | -1% | 0 | 0 | — |
case-06 | fail→fail | 18,422 | 10,842 | -41% | 1 | 1 | 0% | 2,095 | 2,697 | +29% | 0 | 0 | — |
case-07 | pass→pass | 18,796 | 16,147 | -14% | 1 | 1 | 0% | 1,940 | 3,662 | +89% | 0 | 0 | — |
case-08 | pass→pass | 19,875 | 4,416 | -78% | 1 | 1 | 0% | 2,395 | 1,434 | -40% | 0 | 0 | — |
case-09 | pass→pass | 13,369 | 10,196 | -24% | 1 | 1 | 0% | 1,035 | 1,634 | +58% | 0 | 0 | — |
case-10 | pass→pass | 12,576 | 9,852 | -22% | 1 | 1 | 0% | 1,124 | 1,578 | +40% | 0 | 0 | — |
case-11 | fail→pass | 14,324 | 9,801 | -32% | 1 | 1 | 0% | 2,570 | 1,504 | -41% | 0 | 0 | — |
case-12 | pass→pass | 16,642 | 9,545 | -43% | 1 | 1 | 0% | 2,341 | 1,493 | -36% | 0 | 0 | — |
case-13 | fail→pass | 11,367 | 2,445 | -78% | 1 | 1 | 0% | 1,478 | 1,421 | -4% | 0 | 0 | — |
case-14 | fail→pass | 17,296 | 7,313 | -58% | 1 | 1 | 0% | 2,436 | 1,365 | -44% | 0 | 0 | — |
case-15 | pass→pass | 17,094 | 13,030 | -24% | 1 | 1 | 0% | 1,856 | 2,301 | +24% | 0 | 0 | — |
case-16 | pass→pass | 24,054 | 11,084 | -54% | 1 | 1 | 0% | 2,761 | 1,279 | -54% | 0 | 0 | — |
case-17 | fail→pass | 12,827 | 7,508 | -41% | 1 | 1 | 0% | 1,804 | 1,255 | -30% | 0 | 0 | — |
case-18 | pass→pass | 7,937 | 6,178 | -22% | 1 | 1 | 0% | 1,658 | 1,182 | -29% | 0 | 0 | — |
case-19 | fail→pass | 22,833 | 7,120 | -69% | 1 | 1 | 0% | 3,799 | 1,278 | -66% | 0 | 0 | — |
case-20 | pass→fail | 20,797 | 18,120 | -13% | 1 | 1 | 0% | 3,488 | 3,911 | +12% | 0 | 0 | — |
case-21 | pass→pass | 24,680 | 25,780 | +4% | 1 | 1 | 0% | 2,856 | 3,906 | +37% | 0 | 0 | — |
case-22 | pass→pass | 19,267 | 20,233 | +5% | 1 | 1 | 0% | 1,968 | 3,103 | +58% | 0 | 0 | — |
case-23 | fail→pass | 15,665 | 9,456 | -40% | 1 | 1 | 0% | 1,889 | 1,563 | -17% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +39 percentage points is the difference between those two pass rates over the 23 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.