Skip to content

How to Protect Windows from USB-Based Attacks

Issue Description 

Malicious USB drives can install malware or steal data automatically. 

Common Causes 

  • Unknown USB devices 
  • Auto-run enabled 
  • Shared environments 

Step-by-Step Solution 

Step 1: Disable USB Autorun 

  • Open Group Policy Editor → Administrative Templates → Autoplay Policies 
  • Disable Autoplay 

 

Step 2: Scan USB Drives 

  • Insert USB 
  • Right-click drive → Scan with Microsoft Defender 

 

Step 3: Block Unknown USB Devices 

  • Use Device Installation Restrictions (Pro editions) 

 

Step 4: Use Read-Only Mode 

  • Copy files without executing programs 

Explore Further 

  • Use USB control software 

Prevention & Best Practices 

Never plug in unknown USB devices.