Techniques
Sample rules
Windows Share Mount Via Net.EXE
- source: sigma
- technicques:- t1021
- t1021.002
 
Description
Detects when a share is mounted using the “net.exe” utility
Detection logic
condition: all of selection_*
selection_cli:
  CommandLine|contains:
  - ' use '
  - ' \\\\'
selection_img:
- Image|endswith:
  - \net.exe
  - \net1.exe
- OriginalFileName:
  - net.exe
  - net1.exe
