BIOC
Low
✕
Network share discovery via command-line tool
Attackers may use command-line tools to discover mapped shares on the host.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Network Share Discovery (T1135)
Indicator:
Process action type = execution AND target process name = df , smbutil AND target process cmd = *view -g* , *-aH
Preventable: yes