Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0530 — Multi-Event Detection for SMB Admin Share Lateral Movement
DET0530

Multi-Event Detection for SMB Admin Share Lateral Movement

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1468 Analytic 1468
Windows

An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1
[ShareName] Targeted admin share path, such as C$, ADMIN$, IPC$
[TimeWindow] Correlation window between remote file access and remote execution (e.g., 5-10 minutes)
[UserContext] Distinguish expected remote administrators vs. rare/first-time access by specific users
[ProcessList] List of suspicious binaries or tools executed post remote copy (e.g., cmd.exe, powershell.exe, runonce.exe)

Detected Techniques

1

Details

MITRE ID
DET0530
STIX ID
x-mitre-detection-strategy--04cbfa17-64a5-454d-8734-cead02ba5c43
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.