Windows Network Share File Transfers Targeting Credential and Memory Dump Paths

Alerts on network share access to credential-related files using Windows Security Event 5145.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Teymur Kheirkhabarov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-10-22
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies Windows Security event 5145 instances where a process transfers files over a network share and the target path includes well-known credential or memory-dump related filenames and directories (e.g., lsass, minidump, hiberfil, SAM/SECURITY/SYSTEM/NTDS.dit, sqldmpr). This matters because attackers commonly exfiltrate or stage sensitive credential material using standard file transfer mechanisms, blending into normal share access. The rule relies on Windows Security auditing for share access events that include RelativeTargetName values matching the specified sensitive paths.

Related detections9 linkedT1003.002 — drag to rearrange
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Malicious Credential Hive Copy from Volume Shadow Copy
Malicious Mimikatz Credential Access Module Invocation
Windows Print.EXE Sensitive File Dump for Credential Access
Windows PUA: MemProcFS memory dump mounting via -device
Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Pivot detection · T1003.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.