1200KM / simulation
T1135 Network Share Discovery — Attack Simulation
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to…
Technique description
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Network Share Discovery via dir command
Procedure 13daa2cf-195a-43df-a8bd-7dd5ffb607b5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Network Share Discovery PowerShell
Procedure 1b0814d1-bb24-402d-9615-1b20c50733fb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Network Share Discovery command prompt
Procedure 20f1097d-81c1-405c-8380-32174d493bbb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Network Share Discovery - FreeBSD
Procedure 77e468a6-3e5c-45a1-9948-c4b5603747cb; elevation required; cleanup not declared. Not executed or individually validated.
- Network Share Discovery - linux
Procedure 875805bc-9e86-4e87-be86-3a5527315cae; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - shareenumeration
Procedure 987901d1-5b87-4558-a6d9-cffcabc638b8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- View available share drives
Procedure ab39a04f-0c93-4540-9ff2-83f862c385ae; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Share Discovery with PowerView
Procedure b1636f0a-ba82-435c-b699-0d78794d8bfd; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate All Network Shares with Snaffler
Procedure b19d74b7-5e72-450a-8499-82e49e379d1a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- PowerView ShareFinder
Procedure d07e4cc1-98ae-447e-9d31-36cb430d28c4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate All Network Shares with SharpShares
Procedure d1fa2a69-b0a2-4e8a-9112-529b00c19a41; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Network Share Discovery
Procedure f94b5ad9-911c-4eff-9718-fd21899db4f7; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.