kevmap

TechniquesT1021 › T1021.002

T1021.002 SMB/Windows Admin Shares

lateral movement — Windows · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
38
Sigma rules tagged attack.t1021.002
0
KEV CVEs mapped here
<p>Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.</p><p>SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba.</p><p>Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include C$, ADMIN$, and IPC$. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1021.002

Author: Samir Bousseaden, @neu5ron, Tim Shelton · 2020-04-02 (modified 2022-12-27) · logsource: product=zeek service=smb_files · 021310d9-30a6-480a-84b7-eaa69aeb92bb
This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
Techniques: T1021.002
Author: Luca Di Bartolomeo (CrimpSec) · 2024-01-29 · logsource: product=windows category=process_creation · 055fb54c-a8f4-4aee-bd44-f74cf30a0d9d
Detects the execution of SharpMove, a .NET utility performing multiple tasks such as "Task Creation", "SCM" query, VBScript execution using WMI via its PE metadata and command line options.
Techniques: T1021.002
Author: Florian Roth (Nextron Systems) · 2017-03-04 (modified 2024-01-16) · logsource: product=windows service=security · 098d7118-55bc-4912-a836-dc6483a8d150
Detects access to ADMIN$ network share
Techniques: T1021.002
Author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements) · 2019-01-16 (modified 2022-07-11) · logsource: product=windows category=process_creation · 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
Detects execution of "Net.EXE".
Author: frack113 · 2022-08-13 · logsource: product=windows category=ps_script · 1c563233-030e-4a07-af8c-ee0490a66d3a
Adversaries may use to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
Techniques: T1021.002
Author: OTR (Open Threat Research) · 2018-11-28 (modified 2022-08-11) · logsource: product=windows service=security · 214e8f95-100a-4e04-bb31-ef6cba8ce07e
Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
Techniques: T1021.002
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga · 2020-10-12 (modified 2022-12-18) · logsource: product=windows category=file_event · 2f7979ae-f82b-45af-ac1d-2b10e93b0baa
Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
Techniques: T1021.002T1021.003
Author: Bhabesh Raj · 2020-12-14 (modified 2022-09-22) · logsource: product=windows service=security · 32d56ea1-417f-44ff-822b-882873f5f43b
Detects execution of Impacket's psexec.py.
Techniques: T1021.002
Author: oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, wagga · 2020-10-05 (modified 2023-02-21) · logsource: product=windows category=process_creation · 3abd6094-7027-475f-9630-8ab9be7b9725
Detects when an admin share is mounted using net.exe
Techniques: T1021.002
Author: Roberto Rodriguez @Cyb3rWard0g · 2019-08-10 (modified 2021-11-27) · logsource: product=windows service=security · 45545954-4016-43c6-855e-eae8f1c369dc
Detects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers
Techniques: T1021.002
Author: Omer Faruk Celik · 2018-03-20 (modified 2023-11-09) · logsource: product=windows service=system · 52a85084-6989-40c3-8f32-091e12e13f09
Detects the use of smbexec.py tool by detecting a specific service installation
Techniques: T1021.002T1569.002
Author: Samir Bousseaden · 2019-04-03 (modified 2023-03-14) · logsource: product=windows service=security · 52d8b0c6-53d6-439a-9e41-52ad442ad9ad
This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
Techniques: T1021.002
Author: Samir Bousseaden · 2019-04-03 (modified 2024-08-01) · logsource: product=windows service=security · 586a8d6b-6bfe-4ad9-9d78-888cd2fe50c3
Detects remote service activity via remote access to the svcctl named pipe
Techniques: T1021.002
Author: Florian Roth (Nextron Systems), Wojciech Lesicki · 2021-05-26 (modified 2022-11-27) · logsource: product=windows service=system · 5a105d34-05fc-401e-8553-272b45c1522d
Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
Author: Bartlomiej Czyz, Relativity · 2021-01-31 (modified 2023-02-28) · logsource: product=windows category=process_creation · 5bb68627-3198-40ca-b458-49f973db8752
Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-10 (modified 2026-07-20) · logsource: product=windows category=process_creation · 5cdb711b-5740-4fb2-ba88-f7945027afac
Detects rundll32 execution where the DLL is located on a remote location (share). Threat actors can abuse the rundll32.exe binary to execute remote DLLs from a UNC pathh.
Techniques: T1021.002T1218.011
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-10-12 (modified 2022-12-02) · logsource: product=windows category=file_event · 614a7e17-5643-4d89-b6fe-f9df1a79641c
Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
Techniques: T1047T1021.002
Author: Wojciech Lesicki · 2021-06-29 (modified 2024-03-25) · logsource: product=windows category=registry_set · 61a7697c-cb79-42a8-a2ff-5f0cdfae0130
Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.
Author: Bartlomiej Czyz, Relativity · 2021-01-21 (modified 2022-10-05) · logsource: product=windows service=security · 6fb63b40-e02a-403e-9ffd-3bcc1d749442
Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
Author: Chakib Gzenayi (@Chak092), Hosni Mribah · 2020-05-06 (modified 2024-01-25) · logsource: product=windows service=security · 72124974-a68b-4366-b990-d30e0b2a190d
Alerts on Metasploit host's authentications on the domain.
Techniques: T1021.002
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) · 2020-10-12 (modified 2022-10-09) · logsource: product=windows category=image_load · 7707a579-e0d8-4886-a853-ce47e4575aaa
Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
Techniques: T1047T1021.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-21 (modified 2023-07-25) · logsource: product=windows category=process_creation · 7e6237fe-3ddb-438f-9381-9bf9de5af8d0
Detects when an internet hosted webdav share is mounted using the "net.exe" utility
Techniques: T1021.002
Author: Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali · 2019-12-30 (modified 2025-10-22) · logsource: product=windows category=process_creation · 855bc8b5-2ae8-402e-a9ed-b889e6df1900
Detects a copy command or a copy utility execution to or from an Admin share or remote
Author: Mohamed Abdelghani · 2025-10-19 · logsource: product=windows service=smbserver-connectivity · 8d91f6e4-9f3b-4c21-ae41-2c5b7d9f7a12
Detects SMB server connections to shares without signing or encryption enabled. This could indicate potential lateral movement activity using unsecured SMB shares.
Techniques: T1021.002
Author: Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research) · 2020-08-06 (modified 2025-10-17) · logsource: product=windows service=security · b210394c-ba12-4f89-9117-44a2464b9511
Look for non-system accounts SMB accessing a file with write (0x2) access mask via administrative share (i.e C$).
Techniques: T1021.002
Author: OTR (Open Threat Research), @neu5ron · 2018-11-28 (modified 2022-10-09) · logsource: product=zeek service=smb_files · bae2865c-5565-470d-b505-9496c87d0c30
Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
Techniques: T1021.002
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR) · 2020-10-12 (modified 2022-11-26) · logsource: product=windows service=security · c39f0c81-7348-4965-ab27-2fde35a1b641
Detects a threat actor creating a file named `iertutil.dll` in the `C:\Program Files\Internet Explorer\` directory over the network for a DCOM InternetExplorer DLL Hijack scenario.
Techniques: T1021.002T1021.003
Author: Samir Bousseaden · 2019-04-03 (modified 2022-08-11) · logsource: product=windows service=security · c462f537-a1e3-41a6-b5fc-b2c2cef9bf82
detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one
Techniques: T1021.002
Author: Markus Neis · 2017-11-07 (modified 2022-10-09) · logsource: product=windows category=process_creation · c601f20d-570a-4cde-a7d6-e17f99cb8e7f
Detects automated lateral movement by Turla group
Author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2023-08-07 (modified 2023-11-30) · logsource: product=windows category=pipe_created · d36f87ea-c403-44d2-aa79-1a0ac7c24456
Detects default RemCom pipe creation
Techniques: T1021.002T1569.002
Author: Tim Shelton (HAWK.IO) · 2021-12-09 (modified 2023-02-21) · logsource: product=windows category=process_creation · d4498716-1d52-438f-8084-4a603157d131
Detects a when net.exe is called with a password in the command line
Techniques: T1021.002T1078
Author: Florian Roth (Nextron Systems), Wojciech Lesicki · 2021-05-26 (modified 2022-11-27) · logsource: product=windows service=security · d7a95147-145f-4678-b85d-d1ff4a3bb3f6
Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-04-08 · logsource: product=windows category=file_event · efc21479-9e83-41da-8cf1-122e06ba8db3
Detects file creation events indicating NetExec (nxc.exe) execution on the local machine. NetExec is a PyInstaller-bundled binary that extracts its embedded data files to a "_MEI<random>" directory under the Temp folder upon execution. Files dropped under the "\nxc\" sub-directory of that extraction path are unique to NetExec and serve as reliable on-disk indicators of execution. NetExec (formerly CrackMapExec) is a widely used post-exploitation and lateral movement tool used for Active Directory enumeration, credential harvesting, and remote code execution.
Techniques: T1021.002T1059.005
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-02-02 (modified 2023-02-21) · logsource: product=windows category=process_creation · f117933c-980c-4f78-b384-e3d838111165
Detects when a share is mounted using the "net.exe" utility
Techniques: T1021.002
Author: Samir Bousseaden, @neu5ron, Tim Shelton · 2020-04-02 (modified 2022-12-27) · logsource: product=zeek service=smb_files · f1b3a22a-45e6-4004-afb5-4291f9c21166
detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one
Techniques: T1021.002
Author: Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2023-08-07 (modified 2023-11-30) · logsource: product=windows category=pipe_created · f318b911-ea88-43f4-9281-0de23ede628e
Detects default CSExec pipe creation
Techniques: T1021.002T1569.002
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga · 2020-10-12 (modified 2022-12-18) · logsource: product=windows category=image_load · f354eba5-623b-450f-b073-0b5b2773b6aa
Detects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
Techniques: T1021.002T1021.003
Author: Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR) · 2020-10-12 (modified 2022-02-24) · logsource: product=windows service=security · f6c68d5f-e101-4b86-8c84-7d96851fd65c
Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network for a WMI DLL Hijack scenario.
Techniques: T1047T1021.002

Rules tagged at the parent level (attack.t1021) 11

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 22777c9e-873a-4b49-855f-6072ab861a52
Detects instances where an SMB service on an OpenCanary node has had a file open request.
Techniques: T1021T1005
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 6991bc2b-ae2e-447f-bc55-3a1ba04c14e5
Detects instances where an FTP service on an OpenCanary node has had a login attempt.
Techniques: T1190T1021
Psexec Execution mediumtest
Author: omkar72 · 2020-10-30 (modified 2023-02-28) · logsource: product=windows category=process_creation · 730fc21b-eaff-474b-ad23-90fd265d4988
Detects user accept agreement execution in psexec commandline
Techniques: T1569T1021
Author: Chirag Damani · 2026-03-29 · logsource: product=windows category=process_creation · 7638e5fe-600c-4289-a968-f49dd537ec7d
Detects execution of the hacktool NetExec. NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems. Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.
Techniques: T1018T1021
Author: Tim Rauch, Elastic (idea) · 2022-09-27 · logsource: product=windows category=process_creation · 8a3038e8-9c9d-46f8-b184-66234a160f6f
Detects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.
Techniques: T1021
Author: Tim Rauch, Elastic (idea) · 2022-09-27 (modified 2022-12-30) · logsource: product=windows category=process_creation · 9bd04a79-dabe-4f1f-a5ff-92430265c96b
Detects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.
Techniques: T1021
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 9db5446c-b44a-4291-8b89-fcab5609c3b3
Detects instances where a VNC service on an OpenCanary node has had a connection attempt.
Techniques: T1021
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · cd55f721-5623-4663-bd9b-5229cab5237d
Detects instances where an SSH service on an OpenCanary node has had a connection attempt.
Techniques: T1133T1021T1078
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · e9856028-fd4e-46e6-b3d1-10f7ceb95078
Detects instances where an SNMP service on an OpenCanary node has had an OID request.
Techniques: T1016T1021
Author: Josh Nickels · 2024-05-10 · logsource: product=windows category=network_connection · fda34293-718e-4b36-b018-38caab0d1209
Detects an RDP connection originating from a domain controller.
Techniques: T1021
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · ff7139bc-fdb1-4437-92f2-6afefe8884cb
Detects instances where an SSH service on an OpenCanary node has had a login attempt.
Techniques: T1133T1021T1078