T1135 Network Share Discovery — ATT&CK Technique
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the net view \\\\remotesystem command. It can also be used to query shared drives on the local system using net share. For macOS, the sharing -l command lists all shared points used for smb services.
Detection coverage (15)
- Turla Group Lateral Movement critical
- Potential Dridex Activity critical
- Net.EXE Execution low
- PUA - Advanced IP Scanner Execution medium
- PUA - Advanced Port Scanner Execution medium
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell high
- HackTool - SharpView Execution high
- Advanced IP or Port Scanner Execution
- MacOS Network Share Discovery
- Network Share Discovery Via Dir Command
- Windows Administrative Shares Accessed On Multiple Hosts
- Windows File Share Discovery With Powerview
- Windows Large Number of Computer Service Tickets Requested
- Windows Network Share Interaction Via Net
- Windows Special Privileged Logon On Multiple Hosts
Malware using this technique
- BADHATCH
- BlackByte Ransomware
- Ramsay
- Conti
- Medusa Ransomware
- Pupy
- Bazar
- Latrodectus
- Cuba
- Kwampirs
- QakBot
- SILENTTRINITY
- Diavol
- Net
- LunarWeb
- FIVEHANDS
- Emotet
- Sardonic
- PlugX
- CrackMapExec
- BitPaymer
- INC Ransomware
- Qilin
- Empire
- Bad Rabbit
- BlackCat
- BlackByte 2.0 Ransomware
- TrickBot
- KOPILUWAK
- Embargo
- Akira
- LockBit 2.0
- Royal
- WhisperGate
- HELLOKITTY
- Clambling
- LockBit 3.0
- Cobalt Strike
- Avaddon
- Flagpro
- Clop
- IcedID
- Babuk
- RansomHub
- WastedLocker
- Olympic Destroyer
- MURKYTOP
- OSInfo
- Stuxnet
- ShimRat