WYBOT Cybersécurité
FR / EN
BOOK A MEETING →
Home  /  Solutions  /  USB devices
[ USB DEVICES ] · Removable media

The threat also fits on a USB stick

A simple USB stick bypasses firewalls and antivirus by entering the network physically. Wybot detects any removable-media connection and alerts in real time.

WYBOT://USB · MEDIAUSB DETECTED
normal activity▲ USB stick plugged in · RECEPTION host
// USB DEVICE SECURITY

The threat also fits on a USB stick

A simple USB stick can bypass firewalls and antivirus by physically entering the network. It is one of the most underestimated attack vectors, and one of the most effective for attackers.

RISK 01

Malware & ransomware

An infected stick runs its code the moment it is plugged in and spreads a virus or ransomware across the whole network, like Stuxnet// CAS D'ÉCOLE · STUXNETStuxnet, le virus introduit par clé USBDécouvert en 2010, Stuxnet est l'un des programmes malveillants les plus célèbres de l'histoire. Ce ver très sophistiqué visait les systèmes industriels (automates Siemens) des centrifugeuses du programme nucléaire iranien.Son intérêt : le réseau ciblé était isolé d'Internet. Stuxnet s'est propagé par de simples clés USB : preuve qu'aucun réseau, même « air-gappé », n'est à l'abri d'un support amovible piégé., introduit par USB.

RISK 02

Booby-trapped device (BadUSB// MENACE · BADUSBBadUSB : quand le périphérique ment sur sa natureRévélée en 2014, la faille BadUSB exploite le firmware des périphériques USB. Un attaquant reprogramme la puce d'une clé (ou d'un câble, d'un chargeur…) pour qu'elle se déclare comme un autre appareil — le plus souvent un clavier.Une fois branchée, elle tape seule des commandes : ouverture d'un terminal, téléchargement d'un logiciel malveillant, accès distant… en quelques secondes.Le danger : aucun fichier n'est copié et le comportement paraît légitime. Seule la surveillance comportementale du poste permet de le détecter.)

Un périphérique reprogrammé se fait passer pour un clavier et injecte des commandes à l'insu de l'utilisateur, sans aucun fichier détectable.

RISK 03

Data exfiltration

Mass, discreet copying of sensitive data onto removable media: information leaks, intellectual property theft, GDPR non-compliance.

RISK 04

The “dropped” stick

A stick left in a car park or at reception: out of curiosity, an employee plugs it in and opens the door to the attacker themselves.

PROFESSIONAL KEYS: A CRITICAL ISSUE

Some professional-use USB keys grant access to highly sensitive systems. Diverted or hacked, they expose their holder to a very real risk: identity theft, misappropriation of funds, fraudulent legal acts, access to confidential data.

RÉAL key
Notaries

Electronic signature of authenticated deeds and access to the Réal network: a diversion would allow fraudulent deeds to be signed.

Lawyer key (RPVA)
Lawyers

Access to e-Barreau, electronic signature and court proceedings: a compromise exposes confidential case files.

Certificats CSign / SignExpert
Chartered accountants

Signing of tax and social declarations and online procedures on behalf of clients.

RGS / eIDAS certificates
Commercial court clerks

Authentication and signature on the court registry's professional applications.

Professional certificates
Judicial officers

Access to business platforms and signing of deeds: fraudulent access would compromise official proceedings.

Carte CPS
Healthcare professionals

Authentication on healthcare systems and signing of care sheets: access to sensitive medical data.

Carte CPS / CPE
Pharmacists

Authentication and signature in the pharmacy's business software.

SIV key
Car dealers

Access to the Vehicle Registration System (SIV): a hack opens the way to fraudulent registrations and titlesfrauduleux// FRAUDES AU SIVQuand la clé SIV est détournéeLa clé SIV donne un accès direct au fichier national des immatriculations. Compromise, elle devient une arme pour les fraudeurs :Fausses cartes grises : certificats émis pour des véhicules volés ou maquillés.Blanchiment de véhicules volés : réattribution d'une identité « propre ».Usurpation de plaques (doublette) : amendes et délits renvoyés vers un tiers.Responsabilité du professionnel : titulaire de l'habilitation, il est exposé juridiquement et redevable auprès de la Préfecture des cartes grises émises frauduleusement en son nom.PROTÉGER MON ACCÈS SIV →.

WHAT WYBOT DOES · PATENTED TECHNOLOGY

Wybot strengthens USB device security

Thanks to its patented technology, Wybot detects when removable media are plugged in and alerts in real time to regain control of the endpoint before an incident occurs.

USB MONITORING · 24/7

Regain control of removable media

See USB-device monitoring in action during a demo.

REQUEST A TEST →