T1021.002 SMB/Windows Admin Shares
Sub-technique of T1021 Remote Services
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- CobaltStrike Service Installations - Systemcriticaltest · windows
- Potential DCOM InternetExplorer.Application DLL Hijackcriticaltest · windows
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Loadcriticaltest · windows
- Turla Group Lateral Movementcriticaltest · windows
- Wmiprvse Wbemcomn DLL Hijack - Filecriticaltest · windows
- CobaltStrike Service Installations - Securityhightest · windows
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Securityhightest · windows
- First Time Seen Remote Named Pipehightest · windows
- First Time Seen Remote Named Pipe - Zeekhightest · zeek
- HackTool - SharpMove Tool Executionhightest · windows
- Impacket PsExec Executionhightest · windows
- Metasploit Or Impacket Service Installation Via SMB PsExechightest · windows
- Metasploit SMB Authenticationhightest · windows
- Potential CobaltStrike Service Installations - Registryhightest · windows
- Protected Storage Service Accesshightest · windows
- Rundll32 Execution Without Parametershightest · windows
- Rundll32 UNC Path Executionhightest · windows
- SMB Create Remote File Admin Sharehightest · windows
- Suspicious PsExec Executionhightest · windows
- Suspicious PsExec Execution - Zeekhightest · zeek
- T1047 Wmiprvse Wbemcomn DLL Hijackhightest · windows
- Windows Internet Hosted WebDav Share Mount Via Net.EXEhightest · windows
- Wmiprvse Wbemcomn DLL Hijackhightest · windows
- smbexec.py Service Installationhightest · windows
- HackTool - NetExec File Indicatorshighexperimental · windows
Showing 25 of 35.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.