title: Access to ADMIN$ Share description: status: experimental author: Florian Roth logsource: product: windows service: security description: 'The advanced audit policy setting "Object Access > Audit File Share" must be configured for Success/Failure' detection: selection: EventID: 5140 ShareName: Admin$ filter: SubjectAccountName: '*$' condition: selection and not filter falsepositives: - Legitimate administrative activity level: low