Title:
Unsigned or Unencrypted SMB Connection to Share Established
Status:
experimental
Description:Detects SMB server connections to shares without signing or encryption enabled.
This could indicate potential lateral movement activity using unsecured SMB shares.
References:
-https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/overview-server-message-block-signing
Author: Mohamed Abdelghani
Date: 2025-10-19
modified:None
Tags:
- -'attack.lateral-movement'
- -'attack.t1021.002'
Logsource:
- product: windows
- service: smbserver-connectivity
Detection:
selection_shares:
EventID:
'4000'
ShareName|contains:
-'IPC$'
-'ADMIN$'
-'C$'
selection_status:
SigningUsed:
'false'
EncyptionUsed:
'false'
filter_main_local_ips:
- ClientAddress|cidr:
- '127.0.0.0/8'
- '169.254.0.0/16'
- '::1/128'
- 'fe80::/10'
- 'fc00::/7'
- ClientAddress|contains:
- '00000000000000000000000000000001'
- 'FE80000000000000'
- 'FC00000000000000'
- '0200????7F'
- '0200????A9FE'
condition:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Connections from local or private IP addresses to SMB shares without signing or encryption enabled for older systems or misconfigured environments. Apply additional tuning as needed.
Level:
medium