Network Share Discovery T1135

Tactic: Discovery

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.

Events covered

12 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 36 rules share fields, values, and exclusions.

Fields filtered most (37 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine13contains 9, in 2, eq 1, starts_with 1, wildcard 1/lng, /portable, -s , /all, /lng
EventID13eq 134688, 1, 4103, 4104, 5140
Image8ends_with 5, contains 2, eq 1\net.exe, \net1.exe, \advanced_ip_scanner, \advanced_port_scanner, \explorer.exe
OriginalFileName8eq 5, contains 2, in 1net.exe, net1.exe, advanced_ip_scanner, advanced_ip_scanner.exe, advanced_ip_scanner_console.exe
process_name7eq 3, in 2, regex_match 2net.exe, net1.exe, (?i)ipconfig.exe, (?i)net1?.exe, (?i)nltest.exe
Channel4eq 4, in 4
ScriptBlockText4eq 2, in 2, starts_with 1invoke-sharefinder, .getgporeport(), ::getipglobalproperties(), ::getprocesses, dsenumeratedomaintrusts
ShareName4in 2, eq 1, wildcard 1\\\\*\\admin$, \\\\*\\c$, \\\\*\\ipc$, \\*\ADMIN$, \\*\C$
eventtype4eq 4
EventType3contains 1, eq 1, in 1ProcessRollup2, exec, exec_event, network-share-object-access-checked, policy violation
ParentImage3ends_with 2, is_not_null 1, starts_with 1\cmd.exe, \excel.exe, \powershell.exe, \pwsh.exe, \svchost.exe
event.category3eq 3process
event.type3eq 3start
host.os.type3eq 3
unique_targets3gt 330

Top indicator values (376 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
OriginalFileNameeq
net.exe
431
OriginalFileNameeq
net1.exe
344
EventIDeq
4688
3317
EventIDeq
1
2241
EventIDeq
4103
2105
EventIDeq
4104
2269
EventIDeq
5140
28
Imageends_with
\net.exe
349
Imageends_with
\net1.exe
347
event.categoryeq
process
3142
event.typeeq
start
31078
process_nameeq
net.exe
328
process_nameeq
net1.exe
339
unique_targetsgt
30
35
CommandLinecontains
view
22
CommandLinecontains
/lng
22
CommandLinecontains
/portable
22
CommandLinecontains
-s
14
CommandLinecontains
/all
1
CommandLinecontains
/lng
1
CommandLinecontains
/portable
1
CommandLinecontains
accounts
1
CommandLinecontains
group
12
CommandLinecontains
localgroup
1
process_nameregex_match
(?i)ipconfig.exe
22
process_nameregex_match
(?i)net1?.exe
22
process_nameregex_match
(?i)nltest.exe
22
process_nameregex_match
(?i)systeminfo.exe
22
ActionTypene
ListeningConnectionCreated
14
Activityeq
POLICY_VIOLATION
1

Exclusions (52 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinecontains
.dll
1
CommandLineeq
net view \\localhost
1
CommandLinein
sc query "Axway_Integrator"
1
CommandLinein
sc query "Delta enteliVAULT PostgreSQL"
1
CommandLinein
sc query "WERMA-WIN-Connector"
1
CommandLinein
sc query _EWSSynchronizationServer_JDE
1
CommandLinein
sc queryex SCardSvr
1
CommandLinein
sc query SchneiderUPSMySQL
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
ParentImagecontains
gc_service.exe
1
ParentImagecontains
gc_worker.exe
1
ParentImagein
c:\program files\azureconnectedmachineagent\azcmagent.exe
1
ParentImagein
c:\program files\azureconnectedmachineagent\himds.exe
1
ParentImagein
c:\program...
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 9 rules

Elastic 8 rules

Splunk 14 rules

Kusto 5 rules