Linux network share discovery
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Network Share Discovery (T1135)
Severity
Informational
Description
An adversary might use known tools to discover SMB shares within the compromised network.
Attacker's Goals
Exfiltrate or hide sensitive data.
Investigative actions
Check if the action was done using an automation service.
Check if there are any other suspicious activities originated from the same machine/executing user.
Was this helpful?
