{"id":"T1039","name":"Data from Network Shared Drive","url":"https://attack.mitre.org/techniques/T1039","tactics":["collection"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0410","stix_id":"x-mitre-detection-strategy--79eb1874-4762-461b-a748-df85e61f3216","name":"Detection Strategy for Data from Network Shared Drive","url":"https://attack.mitre.org/detectionstrategies/DET0410","analytics":[{"id":"AN1145","stix_id":"x-mitre-analytic--72ba4979-f786-4205-a5da-90874e12813f","name":"Analytic 1145","description":"Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).","url":"https://attack.mitre.org/detectionstrategies/DET0410#AN1145","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5145","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ShareName","description":"Organizations may use custom share paths outside of default C$, Admin$, etc."},{"field":"ProcessName","description":"Common toolsets vary; defenders should tailor to unusual processes for their environment."},{"field":"TimeWindow","description":"Time of day and access duration may need to be tuned to reduce false positives."}],"live":true,"detection_strategies":["DET0410"],"techniques":["T1039"]},{"id":"AN1146","stix_id":"x-mitre-analytic--2d1d5482-b82b-45ff-9563-959766d373ff","name":"Analytic 1146","description":"Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.","url":"https://attack.mitre.org/detectionstrategies/DET0410#AN1146","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open,read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"mount/umount or file copy logs","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"MountPoint","description":"Organization-specific share mount paths may vary (/mnt/share1, /srv/data etc.)"},{"field":"UID","description":"May need to scope to service accounts or user ID patterns specific to enterprise policy."}],"live":true,"detection_strategies":["DET0410"],"techniques":["T1039"]},{"id":"AN1147","stix_id":"x-mitre-analytic--67ca77c9-074f-4c93-9592-cabe9ba8a831","name":"Analytic 1147","description":"Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.","url":"https://attack.mitre.org/detectionstrategies/DET0410#AN1147","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"filesystem and process events","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"open/read/mount operations","data_component":"DC0054","data_component_name":"Drive Access","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"ProcessPath","description":"Script interpreters may vary (e.g., zsh, bash, python, osascript)."},{"field":"SharePath","description":"Network drive mount points may differ across enterprises."}],"live":true,"detection_strategies":["DET0410"],"techniques":["T1039"]}],"live":true,"version":"1.0","techniques":["T1039"]}],"sigma_rules":[{"id":"855bc8b5-2ae8-402e-a9ed-b889e6df1900","title":"Copy From Or To Admin Share Or Sysvol Folder","author":"Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali","status":"test","level":"medium","date":"2019-12-30","modified":"2025-10-22","description":"Detects a copy command or a copy utility execution to or from an Admin share or remote","references":["https://twitter.com/SBousseaden/status/1211636381086339073","https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view","https://www.elastic.co/guide/en/security/current/remote-file-copy-to-a-hidden-share.html","https://www.microsoft.com/en-us/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.collection","attack.exfiltration","attack.t1039","attack.t1048","attack.t1021.002"],"path":"rules/windows/process_creation/proc_creation_win_susp_copy_lateral_movement.yml","techniques":["T1039","T1048","T1021.002"],"cves":[]},{"id":"91c945bc-2ad1-4799-a591-4d00198a1215","title":"Suspicious Access to Sensitive File Extensions","author":"Samir Bousseaden","status":"test","level":"medium","date":"2019-04-03","modified":"2025-10-17","description":"Detects known sensitive file extensions accessed on a network share","references":["Internal Research"],"logsource":{"product":"windows","service":"security"},"tags":["attack.collection","attack.t1039"],"path":"rules/windows/builtin/security/win_security_susp_raccess_sensitive_fext.yml","techniques":["T1039"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}