Data from Network Shared Drive T1039

Tactic: Collection

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 15 rules share fields, values, and exclusions.

Fields filtered most (24 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine5regex_match 3, contains 1, in 1, match 1(?i)(((^|\s+)copy|(xcopy|robocopy)(\.exe)?"?)\s+), cp , mi , move-item, (?i)(Copy\-Item|(^|\s)copy|xcopy(\.exe"?)?|[^\-]cp|[^\-]c...
EventID3eq 34103, 4104, 4688, 5143
OriginalFileName3eq 3net.exe, net1.exe, cmd.exe, powershell.exe, powershell_ise.exe
EventType2eq 2exec, network-share-object-access-checked
Image2ends_with 2, contains 1/mount, /mount_afp, /mount_nfs, \cmd.exe, \powershell.exe
ScriptBlockText2eq 1, in 1dsenumeratedomaintrusts, dsgetsitename, getcomputernameex, invoke-sharefinder, invoke-sharefinderthreaded
event.category2eq 2process
process_name2eq 2net.exe, net1.exe
src_ip2is_not_null 2, ne 10.0.0.0, 127.0.0.1, ::
DACLS1is_not_null 1, starts_with 1A;
OldSD1ne 1newsd
Operation1eq 1, ne 1AddedToSecureLink, AnonymousLinkCreated
RelativeTargetName1ends_with 1.bak, .dmp, .edb
ShareName1in 1\\*\ADMIN$, \\*\C$
Type1eq 1

Top indicator values (103 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLineregex_match
(?i)(((^|\s+)copy|(xcopy|robocopy)(\.exe)?"?)\s+)
22
CommandLineregex_match
(?i)(Copy\-Item|(^|\s)copy|xcopy(\.exe"?)?|[^\-]cp|[^\-]cpi|robocopy(\.exe"?)...
1
OriginalFileNameeq
net.exe
231
OriginalFileNameeq
net1.exe
244
event.categoryeq
process
2142
process_nameeq
net.exe
228
process_nameeq
net1.exe
239
CommandLinecontains
cp
18
CommandLinecontains
mi
13
CommandLinecontains
move-item
1
CommandLinecontains
mv
14
CommandLinecontains
\sysvol\
14
CommandLinecontains
copy
15
CommandLinecontains
copy
112
CommandLinecontains
copy-item
16
CommandLinecontains
cpi
15
CommandLinecontains
move
13
CommandLinein
*use *
1
CommandLinein
*view*
1
CommandLinematch
\\\\*\\*$
1
DACLSstarts_with
A;
1
EventIDeq
4103
1105
EventIDeq
4104
1269
EventIDeq
4688
1317
EventIDeq
5143
1
EventTypeeq
exec
1576
EventTypeeq
network-share-object-access-checked
1
Imagecontains
\powershell.exe
1
Imagecontains
\powershell_ise.exe
1
Imagecontains
\pwsh.exe
1

Exclusions (12 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineeq
net view \\localhost
1
ScriptBlockTexteq
# copyright: (c) 2018, ansible project
1
ScriptBlockTexteq
#ansiblerequires -csharputil ansible.basic
1
ScriptBlockTexteq
#requires -module ansible.moduleutils.addtype
1
ScriptBlockTexteq
ansible.windows.setup
1
ScriptBlockTexteq
discoverwindowscomputerproperties.ps1
1
ScriptBlockTexteq
dsgetsitename
1
ScriptBlockTexteq
nativemethods.netwkstagetinfo(null, 100, out netbuffer);
1
ScriptBlockTexteq
param($sourcetype, $sourceid, $managedentityid, $computeridentity)
1
file.directoryeq
c:\program files (x86)\automox\wdk\win32\winsession
1
shareeq
allowed_shares
1
user.ideq
s-1-5-18
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 6 rules

Splunk 4 rules

Kusto 1 rule

Panther 1 rule