FORENSIA

ATT&CK · T1135

Network Share Discovery

Tactics: discovery

About

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network. File sharing over a Windows network occurs over the SMB protocol. Net can be used to query a remote system for available shared drives using the <code>net view \\\\remotesystem</code> command. It can also be used to query shared drives on the local system using <code>net share</code>. For macOS, the <code>sharing -l</code> command lists all shared points used for smb services.

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

16 known groups

Software

57 malware/tools implement this

PlugXNetCobalt StrikeOSInfoPupyMURKYTOPKwampirsKoadicZebrocyInvisiMoleTrickBotEmpireOlympic DestroyerEmotetShimRatRamsayIcedIDCrackMapExecBazarBitPaymerContiStuxnetBad RabbitClopWastedLockerDEATHRANSOMHELLOKITTYFIVEHANDSCubaBabukAvaddonQakBotDiavolClamblingQuietSieveWhisperGateSILENTTRINITYFlagproAvosLockerBlackCatRoyalKOPILUWAKBADHATCHSardonicAkiraINC RansomwareLunarWebDUSTTRAPLatrodectusBlackByte RansomwareBlackByte 2.0 RansomwareLockBit 2.0LockBit 3.0RansomHubQilinMedusa RansomwareEmbargo

Corpus indicators tagged with this technique

147 indicators in the corpus carry T1135.

IndicatorTypeFamilySevSrc
cve-2021-27076cve851
ece33e4b7e2d26eeca8ad9db4439f9801a7a77e332611116156738b1b0316046sha256ransomware801
3d00e34594dbaba266f301ca37246e06hash802
a1c3520282c81afabdefa4834b96563edf95c3c7hash802
f8965fdce668692c3785afa3559159f9a18287bc0d53abb21902895a8ecf221bsha256ransomware802
5abe477517f51d81061d2e69a9adebdcda80d36667d0afabe103fda4802d33dbsha256ransomware802
c46bac27b5ca151afabd22c5546f78ae2ae3a20dhash802
4c71357de3c0b12094693ca6eff94cadhash802
39bd9c888d3e8110c127ba60cc727d2538bf7da2hashransomware801
99911fce9e0d697c99421b81e8fe2a04hash802
efc71bd23572eec985a6d1bbf61308fdhash802
4200b46a93c6ab059e2b34ce200c4a5bhashransomware802
3ddd90b99ee7ac3ec39e1d22b67c257d273a0970hash802
f694401d8e80bb0f672b1b30fd7b153ahash802
9ddae47ff968343a8c32a5344060257fdc08e2a7bdb9a227c8b3a584ee3c9f1esha256ransomware802
111e8abb4b8592172d597926f47f018chash802
42bcc743c71a9ea083c1c750a398110582796762hashransomware802
6a5f9bd0e4a0c385b98cc7b528be53a95ff9c4ccffa8c1f65448ab792a46186csha256801
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
738d4398e7d11427051093ba8a6f37e51470795chash802
7b6e094d98eb3f695e5856db4d8d22e11898cec9hash802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
f1551d3e5d144eef4e70a29dd3dc52fb22459d1fhash802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
141b2190f51397dbd0dfde0e3904b264c91b6f81febc823ff0c33da980b69944sha256ransomware801

Showing the top 30 by severity of 147.