Windows Security 5145 Network Share Access to Sensitive File Extensions

Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Samir Bousseaden (SigmaHQ), DRL 1.1
Published
2019-04-03
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security Event ID 5145 when an account accesses files on a network share with extensions commonly used for sensitive data and credentials. Attackers may search for and exfiltrate or stage valuable artifacts such as mailbox stores, backup files, crash dumps, directory/credential-related exports, and other high-value formats. It relies on Windows file share auditing telemetry capturing the target filename via RelativeTargetName ending in one of the listed extensions.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.