Unsigned or Unencrypted SMB Connection to Share Established

 Original Source: [Sigma source]
Title: Unsigned or Unencrypted SMB Connection to Share Established
Status: experimental
Description:Detects SMB server connections to shares without signing or encryption enabled. This could indicate potential lateral movement activity using unsecured SMB shares.
References:
  -https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/overview-server-message-block-signing
Author: Mohamed Abdelghani
Date: 2025-10-19
modified:None
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • service: smbserver-connectivity
Detection:
  selection_shares:
    EventID: '4000'
    ShareName|contains:
      -'IPC$'
      -'ADMIN$'
      -'C$'

  selection_status:
SigningUsed:'false' EncyptionUsed:'false'   filter_main_local_ips:
    - ClientAddress|cidr:
      - '127.0.0.0/8'
      - '169.254.0.0/16'
      - '::1/128'
      - 'fe80::/10'
      - 'fc00::/7'
    - ClientAddress|contains:
      - '00000000000000000000000000000001'
      - 'FE80000000000000'
      - 'FC00000000000000'
      - '0200????7F'
      - '0200????A9FE'
  condition:all of selection_* and not 1 of filter_main_*
Falsepositives:
  -Connections from local or private IP addresses to SMB shares without signing or encryption enabled for older systems or misconfigured environments. Apply additional tuning as needed.
Level: medium