1200KM / detection
T1021.002 SMB/Windows Admin Shares — Detection Rules
Detection workspace for T1021.002 SMB/Windows Admin Shares: 36 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- SMB Spoolss Name Piped Usage · test · medium · {"product":"zeek","service":"smb_files"}
- First Time Seen Remote Named Pipe - Zeek · test · high · {"product":"zeek","service":"smb_files"}
- Suspicious PsExec Execution - Zeek · test · high · {"product":"zeek","service":"smb_files"}
- Access To ADMIN$ Network Share · test · low · {"product":"windows","service":"security","definition":"Requirements: The advanced audit policy setting \"Object Access > Audit File Share\" must be configured for Success/Failure"}
- CobaltStrike Service Installations - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- DCERPC SMB Spoolss Named Pipe · test · medium · {"product":"windows","service":"security"}
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security · test · high · {"product":"windows","service":"security"}
- Impacket PsExec Execution · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- First Time Seen Remote Named Pipe · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Metasploit SMB Authentication · test · high · {"product":"windows","service":"security"}
- Metasploit Or Impacket Service Installation Via SMB PsExec · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Protected Storage Service Access · test · high · {"product":"windows","service":"security"}
- SMB Create Remote File Admin Share · test · high · {"product":"windows","service":"security"}
- Suspicious PsExec Execution · test · high · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- Remote Service Activity via SVCCTL Named Pipe · test · medium · {"product":"windows","service":"security","definition":"The advanced audit policy setting \"Object Access > Audit Detailed File Share\" must be configured for Success/Failure"}
- T1047 Wmiprvse Wbemcomn DLL Hijack · test · high · {"product":"windows","service":"security"}
- Unsigned or Unencrypted SMB Connection to Share Established · experimental · medium · {"product":"windows","service":"smbserver-connectivity"}
- CobaltStrike Service Installations - System · test · critical · {"product":"windows","service":"system"}
- smbexec.py Service Installation · test · high · {"product":"windows","service":"system"}
- Potential DCOM InternetExplorer.Application DLL Hijack · test · critical · {"product":"windows","category":"file_event"}
- HackTool - NetExec File Indicators · experimental · high · {"product":"windows","category":"file_event"}
- Wmiprvse Wbemcomn DLL Hijack - File · test · critical · {"product":"windows","category":"file_event"}
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load · test · critical · {"product":"windows","category":"image_load"}
- Wmiprvse Wbemcomn DLL Hijack · test · high · {"product":"windows","category":"image_load"}
- PUA - CSExec Default Named Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- PUA - RemCom Default Named Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- Suspicious New-PSDrive to Admin Share · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - SharpMove Tool Execution · test · high · {"category":"process_creation","product":"windows"}
- Windows Admin Share Mount Via Net.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Windows Internet Hosted WebDav Share Mount Via Net.EXE · test · high · {"category":"process_creation","product":"windows"}
- Windows Share Mount Via Net.EXE · test · low · {"category":"process_creation","product":"windows"}
- Password Provided In Command Line Of Net.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Rundll32 UNC Path Execution · test · high · {"category":"process_creation","product":"windows"}
- Rundll32 Execution Without Parameters · test · high · {"category":"process_creation","product":"windows"}
- Copy From Or To Admin Share Or Sysvol Folder · test · medium · {"category":"process_creation","product":"windows"}
- Potential CobaltStrike Service Installations - Registry · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1021.002 SMB/Windows Admin Shares
MATCH(admin_share_access OR remote_service_creation) AND source_host NOT_IN approved_admin_hosts -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0530 Multi-Event Detection for SMB Admin Share Lateral Movement
AN1468 Analytic 1468
An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Deep Panda · G0009
- Turla · G0010
- APT3 · G0022
- Threat Group-1314 · G0028
- Lazarus Group · G0032
- Sandworm Team · G0034
- APT32 · G0050
- FIN8 · G0061
- Orangeworm · G0071
- APT39 · G0087
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Aquatic Panda · G0143
- Moses Staff · G1009
- FIN13 · G1016
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- Play · G1040
- BlackByte · G1043
- Storm-1811 · G1046
- Velvet Ant · G1047
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.