1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1039 Data from Network Shared Drive — Detection Rules

Detection workspace for T1039 Data from Network Shared Drive: 2 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1039 Data from Network Shared Drive

COUNT(network_share_file_reads BY user, 10m) >= threshold -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0410 Detection Strategy for Data from Network Shared Drive

AN1145 Analytic 1145

Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).

AN1146 Analytic 1146

Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.

AN1147 Analytic 1147

Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1039 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.