- AN1145 · Analytic 1145 — Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).
- AN1146 · Analytic 1146 — Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.
- AN1147 · Analytic 1147 — Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.
AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Data from Network Shared Drive
Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.
Open detection, hunting, mitigation, and evidence workspace
Detection logic
Monitor processes and command-line arguments for actions that could be taken to collect files from a network share. Remote access tools with built-in features may interact directly with the Windows API to gather data. Data may also be acquired through Windows system management tools such as Windows Management Instrumentation and PowerShell.
Observed actors
Correlated CTI and IR reports
Cyber Knowledge context
Use these routes to move from the ATT&CK behavior into explanation, implementation, evidence handling, validation, and defensive operations. Relevance is generated from explicit identifiers/names and governed topic mappings; it is not attribution evidence.
Digital Forensics & Incident Response (DFIR) · Governed topic match · 66/100Timeline reconstruction, ATT CK mapping, CTI, and confidence
Digital Forensics & Incident Response (DFIR) · Governed topic match · 66/100Module 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · Governed topic match · 57/100Evidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · Governed topic match · 54/100Endpoint live response and volatile acquisition
Digital Forensics & Incident Response (DFIR) · Governed topic match · 54/100Network, DNS, proxy, VPN, and email forensics
Digital Forensics & Incident Response (DFIR) · Governed topic match · 54/100Infrastructure as code, CI/CD, artifact provenance, and policy as code
Cloud Security · Governed topic match · 54/100Module 5 — Threat hunting
Blue Team & Defensive Security · Governed topic match · 48/100Network behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · Governed topic match · 45/100Threat modeling and secure architecture
Secure Code & Application Security · Governed topic match · 42/100Input boundaries, injection prevention, and safe output
Secure Code & Application Security · Governed topic match · 42/100Files, parsers, serialization, URL fetching, and isolation
Secure Code & Application Security · Governed topic match · 42/100
MITRE mitigations
No ATT&CK mitigation relationship is published for this technique. Apply risk-based controls and verify scope.