BIOC
Informational
✕
SMB enumeration via command-line tool
Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Network Share Discovery (T1135)
Indicator:
Process action type = execution AND target process name = nmblookup , rpcclient , smbclient , nbtscan Host host os = linux
Preventable: yes