1200KM / detection
T1039 Data from Network Shared Drive — Detection Rules
Detection workspace for T1039 Data from Network Shared Drive: 2 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Access to Sensitive File Extensions · test · medium · {"product":"windows","service":"security"}
- Copy From Or To Admin Share Or Sysvol Folder · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1039 Data from Network Shared Drive
COUNT(network_share_file_reads BY user, 10m) >= threshold -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0410 Detection Strategy for Data from Network Shared Drive
AN1145 Analytic 1145
Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).
AN1146 Analytic 1146
Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.
AN1147 Analytic 1147
Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.