FORENSIA

ATT&CK · T1021.002 · sub-technique

SMB/Windows Admin Shares

Tactics: lateral-movement

About

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba. Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include `C$`, `ADMIN$`, and `IPC$`. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.

Platforms: WindowsParent: T1021 Remote ServicesMITRE ATT&CK ↗

Used by actors

27 known groups

Software

30 malware/tools implement this

ReginPsExecDuquNetNet CrawlerBlackEnergyShamoonCobalt StrikeKwampirszwShellOlympic DestroyerEmotetNotPetyaRyukAnchorLuciferContiStuxnetConfickerDiavolZoxHermeticWizardBrute Ratel C4RoyalBlackByte RansomwarereGeorgLockBit 2.0LockBit 3.0RansomHubQilin

Corpus indicators tagged with this technique

177 indicators in the corpus carry T1021.002.

IndicatorTypeFamilySevSrc
42bcc743c71a9ea083c1c750a398110582796762hashransomware802
4200b46a93c6ab059e2b34ce200c4a5bhashransomware802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11hashransomware801
265a8e89464e32b22553ef16edbab703da7176a7hashransomware801
39bd9c888d3e8110c127ba60cc727d2538bf7da2hashransomware801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
03dd0efa84d145d7d4ed8e240267e5c5hashransomware801
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449hashransomware801
16bad42a397db2e075e09b5b9dd53aaa67b495a4hashransomware801
31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502hashransomware801
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7hashransomware801
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241hashransomware801
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743fhashransomware801
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245hashransomware801
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4hashransomware801
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294chashransomware801
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2hashransomware801
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efchashransomware801
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7dahashransomware801
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347hashransomware801
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
4537b37b65e9dc35640d750f3fa7f4944534f6b1hash803
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141hashransomware801
589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe880hashransomware801

Showing the top 30 by severity of 177.