Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0471 — Detection of Tainted Content Written to Shared Storage
DET0471

Detection of Tainted Content Written to Shared Storage

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1298 Analytic 1298
Windows

Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity.

WinEventLog:Sysmon EventCode=11 WinEventLog:Security EventCode=5145
[SharedPathPrefix] Defines monitored shared directories (e.g., \\server\HR\).
[ExecutableExtensions] Monitored file types dropped in shared paths (e.g., .lnk, .exe, .vbs).
AN1299 Analytic 1299
Linux

Detects script or binary modification within shared NFS/SMB directories followed by process execution from those paths.

auditd:SYSCALL write NSM:Flow smb_files.log
[MountPath] Mount path of monitored shared volumes (e.g., /mnt/shared).
[FilenamePattern] Pattern matching of abnormal or disguised filenames.
AN1300 Analytic 1300
macOS

Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app).

fs:fsevents Directory events (kFSEventStreamEventFlagItemCreated) macos:unifiedlog file writes
[FileExtensionDeception] Monitors use of hidden extensions or double extensions.
[TargetSharedFolder] Defines sensitive shared folders (e.g., /Users/Shared/HR).
AN1301 Analytic 1301
SaaS

Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions.

gcp:workspaceaudit drive.activity logs m365:unified FileUploaded, FileAccessed
[UserUploadRateThreshold] Abnormal upload patterns into shared drives.
[MaliciousFileIndicator] File hash or known-bad filename pattern matching.
AN1302 Analytic 1302
Office Suite

Detects embedded macros or scripts added to shared documents or use of external references to execute code.

m365:defender OfficeTelemetry or DLP
[MacroExecutionPolicy] Controls macro execution based on user or group policy.
[SuspiciousKeywordMatch] Regex match on suspicious VBA function names or calls.

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0471
STIX ID
x-mitre-detection-strategy--cdfe6166-43e9-434a-a961-139edd58ca0c
Analytics
5
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.