Techniques › T1039
T1039 Data from Network Shared Drive
collection — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
2
Sigma rules tagged attack.t1039
0
KEV CVEs mapped here
<p>Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0410 Detection Strategy for Data from Network Shared Drive v1.0
AN1145 WindowsMonitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).Tunable:
ShareNameProcessNameTimeWindowAN1146 LinuxUnusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.Tunable:MountPointUIDAN1147 macOSDetection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.Tunable:ProcessPathSharePath
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1039
Author: Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali
· 2019-12-30 (modified 2025-10-22) · logsource: product=windows category=process_creation · 855bc8b5-2ae8-402e-a9ed-b889e6df1900
Detects a copy command or a copy utility execution to or from an Admin share or remote
Author: Samir Bousseaden
· 2019-04-03 (modified 2025-10-17) · logsource: product=windows service=security · 91c945bc-2ad1-4799-a591-4d00198a1215
Detects known sensitive file extensions accessed on a network share