Network Share Discovery T1135
Tactic: Discovery
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Events covered
12 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 36 rules share fields, values, and exclusions.
Fields filtered most (37 distinct)
These fields appear most often in rule filters.
Top indicator values (376 distinct)
These values appear most often in rule predicates.
Exclusions (52 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 9 rules
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
- HackTool - SharpView Execution
- Net.EXE Execution
- Network share discovery and/or connection via commandline
- Potential Dridex Activity
- PUA - Advanced IP Scanner Execution
- PUA - Advanced Port Scanner Execution
- SharpHound enumeration via SMB named pipes
- Turla Group Lateral Movement
Elastic 8 rules
- Deprecated - PowerShell Script with Discovery Capabilities
- Distributed File System Shares Enumeration via LDAP
- Manual Mount Discovery via /etc/exports or /etc/fstab
- Potential Network Share Discovery
- PowerShell Share Enumeration Script
- PowerShell Suspicious Discovery Related Windows API Functions
- System Service Discovery through built-in Windows Utilities
- Windows Network Enumeration
Splunk 14 rules
- Advanced IP or Port Scanner Execution
- IcedID Discovery Commands (Sysmon)
- IcedID Discovery Commands (Windows Event Log)
- MacOS Network Share Discovery
- Network Share Discovery Via Dir Command
- PowerHuntShares Commands (PowerShell)
- PowerHuntShares Commands (Sysmon)
- PowerHuntShares Commands (Windows Event Log)
- PowerView_SharpView Commands (PowerShell)
- Windows Administrative Shares Accessed On Multiple Hosts
- Windows File Share Discovery With Powerview
- Windows Large Number of Computer Service Tickets Requested
- Windows Network Share Interaction Via Net
- Windows Special Privileged Logon On Multiple Hosts