Techniques
Sample rules
Windows Share Mount Via Net.EXE
- source: sigma
- technicques:
- t1021
- t1021.002
Description
Detects when a share is mounted using the “net.exe” utility
Detection logic
condition: all of selection_*
selection_cli:
CommandLine|contains:
- ' use '
- ' \\\\'
selection_img:
- Image|endswith:
- \net.exe
- \net1.exe
- OriginalFileName:
- net.exe
- net1.exe