Share And Session Enumeration Using Net.EXE

 Original Source: [Sigma source]
Title: Share And Session Enumeration Using Net.EXE
Status: stable
Description:Detects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
References:
  -https://eqllib.readthedocs.io/en/latest/analytics/b8a94d2f-dc75-4630-9d73-1edc6bd26fff.html
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1018/T1018.md
Author: Endgame, JHasenbusch (ported for oscd.community)
Date: 2018-10-30
modified:2023-02-21
Tags:
  • -'attack.discovery'
  • -'attack.t1018'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\net.exe'
      - '\net1.exe'
    - OriginalFileName:
      - 'net.exe'
      - 'net1.exe'
  selection_cli:
    CommandLine|contains: 'view'
  filter:
    CommandLine|contains: '\\\\'
  condition:all of selection_* and not filter
Falsepositives:
  -Legitimate use of net.exe utility by legitimate user
Level: low