// MITRE ATT&CK
T1021.002 · SMB/Windows Admin Shares
Sub-technique of T1021 · Remote Services.
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on th...
How to detect & mitigate it
Detecting SMB/Windows Admin Shares starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1021.005
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1550
Use Alternate Authentication Material T1021
Remote Services
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1550
Use Alternate Authentication Material T1021
Remote Services
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.