Network Share Discovery

T1135

Technique.View on attack.mitre.org

About this technique

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.

File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the net view \\\\remotesystem command. It can also be used to query shared drives on the local system using net share. For macOS, the sharing -l command lists all shared points used for smb services.

Detection rules13

Rules on DetectionCode tagged with T1135.

Sigma4

RuleLevelLog source
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shellhighwindows / process_creation
HackTool - SharpView Executionhighwindows / process_creation
PUA - Advanced IP Scanner Executionmediumwindows / process_creation
PUA - Advanced Port Scanner Executionmediumwindows / process_creation

Splunk9

RuleTypeRiskData source
Advanced IP or Port Scanner ExecutionAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
MacOS Network Share DiscoveryAnomalyNULLOsquery Results
Network Share Discovery Via Dir CommandHuntingNULLWindows Event Log Security 5140
Windows Administrative Shares Accessed On Multiple HostsTTPNULLWindows Event Log Security 5140, Windows Event Log Security 5145
Windows File Share Discovery With PowerviewTTPNULLPowershell Script Block Logging 4104
Windows Large Number of Computer Service Tickets RequestedAnomalyNULLWindows Event Log Security 4769
Windows Network Share Interaction Via NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Network Share Interaction With NetTTPNULLSysmon EventID 1
Windows Special Privileged Logon On Multiple HostsTTPNULLWindows Event Log Security 4672

Groups16

Software57

Show 33 more

Campaigns4

Procedure examples77

Groups16

Used byProcedure example
GroupAPT1

APT1 listed connected network shares.

GroupAPT32

APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$.

GroupAPT38

APT38 has enumerated network shares on a compromised host.

GroupAPT39

APT39 has used the post exploitation tool CrackMapExec to enumerate network shares.

GroupAPT41

APT41 used the net share command as part of network reconnaissance.

GroupBlackByte

BlackByte enumerated network shares on victim devices.

GroupChimera

Chimera has used net share and net view to identify network shares of interest.

GroupDarkVishnya

DarkVishnya scanned the network for public shared folders.

View all 16 groups examples

Software57

Used byProcedure example
MalwareAkira

Akira can identify remote file shares for encryption.

MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

MalwareAvosLocker

AvosLocker has enumerated shared drives on a compromised network.

MalwareBabuk

Babuk has the ability to enumerate network shares.

MalwareBad Rabbit

Bad Rabbit enumerates open SMB shares on internal victim networks.

MalwareBADHATCH

BADHATCH can check a user's access to the C$ share on a compromised machine.

MalwareBazar

Bazar can enumerate shared drives on the domain.

MalwareBitPaymer

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

View all 57 software examples

Campaigns4

Used byProcedure example
CampaignC0015

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.

CampaignLeviathan Australian Intrusions

Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net share` command as part of their advanced reconnaissance.

CampaignOperation Wocao

During Operation Wocao, threat actors discovered network disks mounted to the system using netstat.

References2

  1. TechNet Shared Folder Open source
    Microsoft. (n.d.). Share a Folder or Drive. Retrieved June 30, 2017.
  2. Wikipedia Shared Resource Open source
    Wikipedia. (2017, April 15). Shared resource. Retrieved June 30, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.