// MITRE ATT&CK
T1021.002 · SMB/Windows Admin Shares
Sub-técnica de T1021 · Remote Services.
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user. SMB is a file, printer, and serial port sharing protocol for Windows machines on th...
¿Cómo detectarlo y mitigarlo?
La detección de SMB/Windows Admin Shares parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Técnicas relacionadas
T1021.005
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1550
Use Alternate Authentication Material T1021
Remote Services
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1550
Use Alternate Authentication Material T1021
Remote Services
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.