{"id":"T1135","name":"Network Share Discovery","url":"https://attack.mitre.org/techniques/T1135","tactics":["discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0182","stix_id":"x-mitre-detection-strategy--e7870b55-7420-444a-9751-99fb5fbf4cd9","name":"Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS","url":"https://attack.mitre.org/detectionstrategies/DET0182","analytics":[{"id":"AN0513","stix_id":"x-mitre-analytic--8a2537c3-9e9a-482d-81e2-281f88cf8878","name":"Analytic 0513","description":"Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\\\host\\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.","url":"https://attack.mitre.org/detectionstrategies/DET0182#AN0513","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=17","data_component":"DC0048","data_component_name":"Named Pipe Metadata","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"etw:Microsoft-Windows-RPC","channel":"rpc_call: srvsvc.NetShareEnum / NetShareEnumAll from non-admin or unusual processes","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"etw-microsoft-windows-rpc"}],"mutable_elements":[{"field":"BurstHostThreshold","description":"Minimum number of unique destination hosts over SMB within TimeWindow to treat as scanning (e.g., ≥5)."},{"field":"TimeWindow","description":"Correlation window between the discovery process start and SMB fan-out (default 10m)."},{"field":"AllowedDiscoveryAccounts","description":"Service/admin accounts legitimately running inventory scripts."},{"field":"PipeNameAllowList","description":"Pipes (e.g., \\PIPE\\spoolss) normally accessed by management agents; exclude from alerts."}],"live":true,"detection_strategies":["DET0182"],"techniques":["T1135"]},{"id":"AN0514","stix_id":"x-mitre-analytic--2de35397-ef03-4ffe-b531-d7ad61a6f41d","name":"Analytic 0514","description":"CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window.","url":"https://attack.mitre.org/detectionstrategies/DET0182#AN0514","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve of smbclient, smbmap, rpcclient, nmblookup, crackmapexec smb","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"connection: TCP connections to ports 139/445 to multiple hosts","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"smb_command: TreeConnectAndX to \\\\*\\IPC$ / srvsvc or Trans2/NT_CREATE for listing shares","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BurstHostThreshold","description":"Minimum unique hosts to flag (e.g., ≥5)."},{"field":"TimeWindow","description":"Correlation window between tool exec and SMB fan-out (default 10m)."},{"field":"ApprovedInventoryHosts","description":"IPs of vulnerability scanners or config mgmt systems."}],"live":true,"detection_strategies":["DET0182"],"techniques":["T1135"]},{"id":"AN0515","stix_id":"x-mitre-analytic--5a9238a9-acd0-44f0-bd41-f86ef433775b","name":"Analytic 0515","description":"Use of native/mac tools (sharing -l, smbutil view, mount_smbfs) or scripts to enumerate SMB shares across many hosts, followed by outbound SMB connections observed in PF/Zeek logs.","url":"https://attack.mitre.org/detectionstrategies/DET0182#AN0515","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC: Process execution of \"sharing -l\", \"smbutil view\", \"mount_smbfs\"","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"Command line contains smbutil view //, mount_smbfs //","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Firewall","channel":"Outbound connections to 139/445 to multiple destinations","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-firewall"},{"name":"NSM:Flow","channel":"connection: SMB connections to multiple internal hosts","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BurstHostThreshold","description":"Minimum unique SMB destinations (e.g., ≥3–5 in smaller mac fleets)."},{"field":"TimeWindow","description":"Correlation window between exec and SMB connections (default 10m)."},{"field":"AllowedMgmtTools","description":"Jamf/IT scripts legitimately running smbutil/mount_smbfs."}],"live":true,"detection_strategies":["DET0182"],"techniques":["T1135"]}],"live":true,"version":"1.0","techniques":["T1135"]}],"sigma_rules":[{"id":"183e7ea8-ac4b-4c23-9aec-b3dac4e401ac","title":"Net.EXE Execution","author":"Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements)","status":"test","level":"low","date":"2019-01-16","modified":"2022-07-11","description":"Detects execution of \"Net.EXE\".","references":["https://pentest.blog/windows-privilege-escalation-methods-for-pentesters/","https://eqllib.readthedocs.io/en/latest/analytics/4d2e7fc1-af0b-4915-89aa-03d25ba7805e.html","https://eqllib.readthedocs.io/en/latest/analytics/e61f557c-a9d0-4c25-ab5b-bbc46bb24deb.html","https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1007/T1007.md#atomic-test-2---system-service-discovery---netexe"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1007","attack.t1049","attack.t1018","attack.t1135","attack.t1201","attack.t1069.001","attack.t1069.002","attack.t1087.001","attack.t1087.002","attack.lateral-movement","attack.t1021.002","attack.s0039","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_net_execution.yml","techniques":["T1007","T1049","T1018","T1135","T1201","T1069.001","T1069.002","T1087.001","T1087.002","T1021.002"],"cves":[]},{"id":"54773c5f-f1cc-4703-9126-2f797d96a69d","title":"PUA - Advanced Port Scanner Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-12-18","modified":"2023-02-07","description":"Detects the use of Advanced Port Scanner.","references":["https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/Advanced%20Port%20Scanner"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1046","attack.t1135"],"path":"rules/windows/process_creation/proc_creation_win_pua_advanced_port_scanner.yml","techniques":["T1046","T1135"],"cves":[]},{"id":"b2317cfa-4a47-4ead-b3ff-297438c0bc2d","title":"HackTool - SharpView Execution","author":"frack113","status":"test","level":"high","date":"2021-12-10","modified":"2023-02-14","description":"Adversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems","references":["https://github.com/tevora-threat/SharpView/","https://github.com/PowerShellMafia/PowerSploit/blob/d943001a7defb5e0d1657085a77a0e78609be58f/Recon/PowerView.ps1","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-4---system-discovery-using-sharpview"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1049","attack.t1069.002","attack.t1482","attack.t1135","attack.t1033"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sharpview.yml","techniques":["T1049","T1069.002","T1482","T1135","T1033"],"cves":[]},{"id":"bef37fa2-f205-4a7b-b484-0759bfd5f86f","title":"PUA - Advanced IP Scanner Execution","author":"Nasreddine Bencherchali (Nextron Systems), @ROxPinTeddy","status":"test","level":"medium","date":"2020-05-12","modified":"2023-02-07","description":"Detects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.","references":["https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/","https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html","https://labs.f-secure.com/blog/prelude-to-ransomware-systembc","https://assets.documentcloud.org/documents/20444693/fbi-pin-egregor-ransomware-bc-01062021.pdf","https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer","https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/Advanced%20IP%20Scanner"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1046","attack.t1135"],"path":"rules/windows/process_creation/proc_creation_win_pua_advanced_ip_scanner.yml","techniques":["T1046","T1135"],"cves":[]},{"id":"c3d76afc-93df-461e-8e67-9b2bad3f2ac4","title":"File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell","author":"@Kostastsale","status":"test","level":"high","date":"2022-12-22","modified":"2024-08-23","description":"Detects the initial execution of \"cmd.exe\" which spawns \"explorer.exe\" with the appropriate command line arguments for opening the \"My Computer\" folder.\n","references":["https://ss64.com/nt/shell.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1135"],"path":"rules/windows/process_creation/proc_creation_win_explorer_folder_shortcut_via_shell_binary.yml","techniques":["T1135"],"cves":[]},{"id":"c601f20d-570a-4cde-a7d6-e17f99cb8e7f","title":"Turla Group Lateral Movement","author":"Markus Neis","status":"test","level":"critical","date":"2017-11-07","modified":"2022-10-09","description":"Detects automated lateral movement by Turla group","references":["https://securelist.com/the-epic-turla-operation/65545/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.g0010","attack.execution","attack.t1059","attack.lateral-movement","attack.t1021.002","attack.discovery","attack.t1083","attack.t1135","detection.emerging-threats"],"path":"rules-emerging-threats/2014/TA/Turla/proc_creation_win_apt_turla_commands_critical.yml","techniques":["T1059","T1021.002","T1083","T1135"],"cves":[]},{"id":"e6eb5a96-9e6f-4a18-9cdd-642cfda21c8e","title":"Potential Dridex Activity","author":"Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"stable","level":"critical","date":"2019-01-10","modified":"2023-02-03","description":"Detects potential Dridex acitvity via specific process patterns","references":["https://app.any.run/tasks/993daa5e-112a-4ff6-8b5a-edbcec7c7ba3","https://redcanary.com/threat-detection-report/threats/dridex/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1055","attack.discovery","attack.t1135","attack.t1033","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/Dridex/proc_creation_win_malware_dridex.yml","techniques":["T1055","T1135","T1033"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}