Technique.View on attack.mitre.org
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the net view \\\\remotesystem command. It can also be used to query shared drives on the local system using net share. For macOS, the sharing -l command lists all shared points used for smb services.
Rules on DetectionCode tagged with T1135.
| Rule | Level | Log source |
|---|---|---|
| File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell | high | windows / process_creation |
| HackTool - SharpView Execution | high | windows / process_creation |
| PUA - Advanced IP Scanner Execution | medium | windows / process_creation |
| PUA - Advanced Port Scanner Execution | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Advanced IP or Port Scanner Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| MacOS Network Share Discovery | Anomaly | NULL | Osquery Results |
| Network Share Discovery Via Dir Command | Hunting | NULL | Windows Event Log Security 5140 |
| Windows Administrative Shares Accessed On Multiple Hosts | TTP | NULL | Windows Event Log Security 5140, Windows Event Log Security 5145 |
| Windows File Share Discovery With Powerview | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Large Number of Computer Service Tickets Requested | Anomaly | NULL | Windows Event Log Security 4769 |
| Windows Network Share Interaction Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Network Share Interaction With Net | TTP | NULL | Sysmon EventID 1 |
| Windows Special Privileged Logon On Multiple Hosts | TTP | NULL | Windows Event Log Security 4672 |
| Used by | Procedure example |
|---|---|
| GroupAPT1 | APT1 listed connected network shares. |
| GroupAPT32 | APT32 used the |
| GroupAPT38 | APT38 has enumerated network shares on a compromised host. |
| GroupAPT39 | APT39 has used the post exploitation tool CrackMapExec to enumerate network shares. |
| GroupAPT41 | APT41 used the |
| GroupBlackByte | BlackByte enumerated network shares on victim devices. |
| GroupChimera | Chimera has used |
| GroupDarkVishnya | DarkVishnya scanned the network for public shared folders. |
| Used by | Procedure example |
|---|---|
| MalwareAkira | Akira can identify remote file shares for encryption. |
| MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| MalwareAvosLocker | AvosLocker has enumerated shared drives on a compromised network. |
| MalwareBabuk | Babuk has the ability to enumerate network shares. |
| MalwareBad Rabbit | Bad Rabbit enumerates open SMB shares on internal victim networks. |
| MalwareBADHATCH | BADHATCH can check a user's access to the C$ share on a compromised machine. |
| MalwareBazar | Bazar can enumerate shared drives on the domain. |
| MalwareBitPaymer | BitPaymer can search for network shares on the domain or workgroup using |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares. |
| CampaignLeviathan Australian Intrusions | Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance. |
| CampaignOperation Wocao | During Operation Wocao, threat actors discovered network disks mounted to the system using netstat. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.