1200KM / sigma-rule
Suspicious Get Information for SMB Share - PowerShell Module — Sigma Rule
Sigma rule 6942bd25-5970-40ab-af49-944247103358. Suspicious Get Information for SMB Share - PowerShell Module — Sigma Rule. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Rule metadata and linked tags
Author: frack113. Source status: test; severity: low. Source dates: 2021-12-15 / 2022-12-02.
{
"product": "windows",
"category": "ps_module",
"definition": "0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 6d40beb128b1ddb2740b81ed8160ff3c1766df24aa0da83bb90d23970a850101
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Suspicious Get Information for SMB Share - PowerShell Module
id: 6942bd25-5970-40ab-af49-944247103358
status: test
description: |
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and
to identify potential systems of interest for Lateral Movement.
Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md
author: frack113
date: 2021-12-15
modified: 2022-12-02
tags:
- attack.discovery
- attack.t1069.001
logsource:
product: windows
category: ps_module
definition: 0ad03ef1-f21b-4a79-8ce8-e6900c54b65b
detection:
selection:
- Payload|contains: get-smbshare
- ContextInfo|contains: get-smbshare
condition: selection
falsepositives:
- Administrator script
level: low
False positives
- Administrator script
Source references
Connected ecosystem references
Exact source-tagged techniques
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.