Windows Security 5140 File Share Access to MSHTML_C7 IP-Named Paths

Alerts on Windows file share access events targeting \MSHTML_C7\ shares with an IP-like naming pattern (EventID 5140).

FreeReviewedSigma · High · v5
Product
windows
Service
security
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-07-13
Updated
2026-07-31

What it detects

This rule flags Windows Security EventID 5140 for access to a file share where the share name and local path both include \MSHTML_C7\ and an IPv4-like dotted-quad pattern. Attackers may use such naming schemes to stage or reach resources during exploitation attempts. It relies on Windows file share access auditing telemetry (5140) and matching patterns in the share name and share local path fields.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.