// REFERENCE
5145 — Network share access was checked
Log: Security
Medium risk
Detailed share-access auditing: it logs each file accessed within the share (more granular than 5140). Key to spotting tools that walk SYSVOL/NETLOGON or exfiltrate files over SMB. It's high-volume; filter by relevant file name.
Related tools
Work with this in:
Related
5140
5140 — A network share was accessed 5142
5142 — A network share was added 5143
5143 — A network share was modified 4648
4648 — Logon using explicit credentials
5140 — A network share was accessed 5142
5142 — A network share was added 5143
5143 — A network share was modified 4648
4648 — Logon using explicit credentials
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.