MITRE ATT&CK technique
Network Share Discovery detection rulesT1135
Network Share Discovery (T1135) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 7 community-maintained Sigma detection rules in the library mapped to T1135 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Potential Dridex Activity
criticalDetects potential Dridex acitvity via specific process patterns
windows · process_creation
Turla Group Lateral Movement
criticalDetects automated lateral movement by Turla group
windows · process_creation
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
highDetects the initial execution of "cmd.exe" which spawns "explorer.exe" with the appropriate command line arguments for opening the "My Computer" folder.
windows · process_creation
HackTool - SharpView Execution
highAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
PUA - Advanced IP Scanner Execution
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · process_creation
PUA - Advanced Port Scanner Execution
mediumDetects the use of Advanced Port Scanner.
windows · process_creation
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation