OpenCanary SMB service records file open requests

Triggers when OpenCanary logs an SMB file open request to its monitored host.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Lateral Movement → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags when an OpenCanary node handling SMB receives a file open request. Such events can indicate attempted SMB enumeration or access attempts used for collection and lateral movement. The detection relies on OpenCanary application telemetry where file open activity is logged as logtype 5000.

Related detections9 linkedT1005 — drag to rearrange
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Suspicious Astaroth Spambot Browser Profile Staging Directory (via file_event)
Suspicious Browser and Wallet Credential Theft via JavaScript Stealer
Suspicious WhatsAppBackup Data Staging Archive Creation
Suspicious Environment File Credential Search via findstr (via process_creation)
Suspicious LocalAccountTokenFilterPolicy Enabled via Registry by BlackByte Ransomware
Suspicious RDP Bitmap Cache Temp Files Written by mstsc in Rogue RDP Campaign (via file_event)
Suspicious Azure CLI Disk Snapshot and Copy for Data Theft
Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
OpenCanary SMB service records file open requests
Pivot detection · T1005 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.