1200KM / simulation
T1021.002 SMB/Windows Admin Shares — Attack Simulation
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba.…
Technique description
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Copy and Execute File with PsExec
Procedure 0eb03d41-79e4-4393-8e57-6344856be1cf; elevation required; cleanup not declared. Not executed or individually validated.
- Map admin share
Procedure 3386975b-367a-4fbb-9d77-4dcf3639ffd3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Map Admin Share PowerShell
Procedure 514e9cd7-9207-4882-98b1-c8f791bae3c5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execute command writing output to local Admin Share
Procedure d41aaab5-bdfe-431d-a3d5-c29e9136ff46; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Deep Panda · G0009
- Turla · G0010
- APT3 · G0022
- Threat Group-1314 · G0028
- Lazarus Group · G0032
- Sandworm Team · G0034
- APT32 · G0050
- FIN8 · G0061
- Orangeworm · G0071
- APT39 · G0087
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Aquatic Panda · G0143
- Moses Staff · G1009
- FIN13 · G1016
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- Play · G1040
- BlackByte · G1043
- Storm-1811 · G1046
- Velvet Ant · G1047
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.