Files
blue-team-tools/unsupported/windows/win_susp_failed_hidden_share_mount.yml
2023-04-23 15:42:01 +02:00

29 lines
840 B
YAML

title: Failed Mounting of Hidden Share
id: 1c3be8c5-6171-41d3-b792-cab6f717fcdb
status: unsupported
description: Detects repeated failed (outgoing) attempts to mount a hidden share
references:
- https://twitter.com/moti_b/status/1032645458634653697
- https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Cyber-Security/SiSyPHuS/AP10/Logging_Configuration_Guideline.pdf?__blob=publicationFile&v=5
author: Fabian Franz
date: 2022/08/30
modified: 2023/02/24
tags:
- attack.t1021.002
- attack.lateral_movement
logsource:
product: windows
service: smbclient-security
detection:
selection:
EventID: 31010
ShareName|endswith: '$'
timeframe: 1m
condition: selection | count() > 10
fields:
- ShareName
falsepositives:
- Legitimate administrative activity
- Faulty scripts
level: medium