1200KM / detection
T1135 Network Share Discovery — Detection Rules
Detection workspace for T1135 Network Share Discovery: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell · test · high · {"product":"windows","category":"process_creation"}
- HackTool - SharpView Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Advanced IP Scanner Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - Advanced Port Scanner Execution · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0182 Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS
AN0513 Analytic 0513
Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.
AN0514 Analytic 0514
CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window.
AN0515 Analytic 0515
Use of native/mac tools (sharing -l, smbutil view, mount_smbfs) or scripts to enumerate SMB shares across many hosts, followed by outbound SMB connections observed in PF/Zeek logs.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.