T1021.002 SMB/Windows Admin Shares — ATT&CK Technique
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba. Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include `C$`, `ADMIN$`, and `IPC$`. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.
Detection coverage (50)
- Net.EXE Execution low
- Suspicious PsExec Execution - Zeek high
- First Time Seen Remote Named Pipe - Zeek high
- SMB Spoolss Name Piped Usage medium
- CobaltStrike Service Installations - Security high
- Access To ADMIN$ Network Share low
- DCERPC SMB Spoolss Named Pipe medium
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security high
- Impacket PsExec Execution high
- First Time Seen Remote Named Pipe high
- Metasploit SMB Authentication high
- Protected Storage Service Access high
- Metasploit Or Impacket Service Installation Via SMB PsExec high
- SMB Create Remote File Admin Share high
- Suspicious PsExec Execution high
- Remote Service Activity via SVCCTL Named Pipe medium
- T1047 Wmiprvse Wbemcomn DLL Hijack high
- Unsigned or Unencrypted SMB Connection to Share Established medium
- CobaltStrike Service Installations - System critical
- smbexec.py Service Installation high
- Potential DCOM InternetExplorer.Application DLL Hijack critical
- HackTool - NetExec File Indicators high
- Wmiprvse Wbemcomn DLL Hijack - File critical
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load critical
- Wmiprvse Wbemcomn DLL Hijack high
- PUA - RemCom Default Named Pipe medium
- PUA - CSExec Default Named Pipe medium
- Suspicious New-PSDrive to Admin Share medium
- HackTool - SharpMove Tool Execution high
- Password Provided In Command Line Of Net.EXE medium
- Windows Admin Share Mount Via Net.EXE medium
- Windows Internet Hosted WebDav Share Mount Via Net.EXE high
- Windows Share Mount Via Net.EXE low
- Rundll32 UNC Path Execution high
- Rundll32 Execution Without Parameters high
- Copy From Or To Admin Share Or Sysvol Folder medium
- Potential CobaltStrike Service Installations - Registry high
- Detect PsExec With accepteula Flag
- Executable File Written in Administrative SMB Share
- Impacket Lateral Movement smbexec CommandLine Parameters
- Impacket Lateral Movement Commandline Parameters
- Impacket Lateral Movement WMIExec Commandline Parameters
- Turla Group Lateral Movement critical
- Windows PUA Named Pipe
- Windows RMM Named Pipe
- Windows Special Privileged Logon On Multiple Hosts
- Windows Suspicious C2 Named Pipe
- Windows Suspicious Named Pipe
- Windows Theme File Creation in Unusual Location
- SMB Traffic Spike
Malware using this technique
- Stuxnet
- reGeorg
- RansomHub
- Emotet
- Olympic Destroyer
- Regin
- Conti
- Diavol
- Lucifer
- BlackEnergy
- zwShell
- NotPetya
- Conficker
- Anchor
- Cobalt Strike
- LockBit 3.0
- Royal
- Shamoon
- BlackByte Ransomware
- Ryuk
- LockBit 2.0
- Kwampirs
- Qilin
- PsExec
- Zox
- Net Crawler
- HermeticWizard
- Net
- Brute Ratel C4
- Duqu