Windows Share Mount Via Net.EXE

Rule Info

Name
Windows Share Mount Via Net.EXE
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects when a share is mounted using the "net.exe" utility
Date
2023-02-02 00:00:00
Modified
2023-02-21 00:00:00
Id
f117933c-980c-4f78-b384-e3d838111165
Tags
attack.lateral_movement attack.t1021.002 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
chore: promote older rules status from `experimental` to `test` (#4651)
2024-01-01
Nasreddine Bencherchali
Merge PR #4482 From @nasbench - Add New Automation Workflows
2023-10-18
Nasreddine Bencherchali
feat: multiple fixes and updates
2023-02-21
Nasreddine Bencherchali
fix: apply escape suggestion
2023-02-02
Nasreddine Bencherchali
fix: add missing modified field
2023-02-02
Nasreddine Bencherchali
feat: more updates
2023-02-02
frack113
old experimental rule promotion
2022-10-09
frack113
Normalization of rule names
2022-02-22
frack113
Order rules
2021-12-04
Bhabesh Rai
Merging upstream updates
2021-07-01
wagga40
Added missing "modified" fields. Removed trailing wildcard.
2021-06-27
wagga40
Updated rules with modifiers instead of '*' and remove trailing '\\'
2021-06-27
svch0stz
Update win_net_use_admin_share.yml
2020-10-07
svch0stz
Create win_net_use_admin_share.yml
2020-10-05