Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1039 — Data from Network Shared Drive
T1039

Data from Network Shared Drive

Collection
TLP:CLEAR

Description

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.

MITRE ATT&CK Detection Strategies
1

DET0410 Detection Strategy for Data from Network Shared Drive
AN1146 Linux

Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer.

auditd:SYSCALL linux:syslog
AN1147 macOS

Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes.

macos:unifiedlog fs:fsusage
AN1145 Windows

Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).

WinEventLog:Security WinEventLog:Sysmon

Details

Platforms
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.