1200kmSECURITY RESEARCH

1200KM / sigma-rule

Suspicious Get Information for SMB Share - PowerShell Module — Sigma Rule

Sigma rule 6942bd25-5970-40ab-af49-944247103358. Suspicious Get Information for SMB Share - PowerShell Module — Sigma Rule. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.

Rule metadata and linked tags

Author: frack113. Source status: test; severity: low. Source dates: 2021-12-15 / 2022-12-02.

{
  "product": "windows",
  "category": "ps_module",
  "definition": "0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"
}

Pinned original Sigma rule · Detection Rule License 1.1

Source SHA-256: 6d40beb128b1ddb2740b81ed8160ff3c1766df24aa0da83bb90d23970a850101

Detection logic

Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.

title: Suspicious Get Information for SMB Share - PowerShell Module
id: 6942bd25-5970-40ab-af49-944247103358
status: test
description: |
    Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and
    to identify potential systems of interest for Lateral Movement.
    Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md
author: frack113
date: 2021-12-15
modified: 2022-12-02
tags:
    - attack.discovery
    - attack.t1069.001
logsource:
    product: windows
    category: ps_module
    definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
    selection:
        - Payload|contains: get-smbshare
        - ContextInfo|contains: get-smbshare
    condition: selection
falsepositives:
    - Administrator script
level: low

Original YAML and metadata in JSON

False positives

  • Administrator script

Source references

Connected ecosystem references

Exact source-tagged techniques

Telemetry review

Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.