Windows SMBClient Connectivity: Failed Outbound SMB Connection Attempts to Internet-Facing Servers

Identifies Windows SMB client failures to connect to external SMB servers by correlating specific SMB connectivity event IDs with non-private remote addresses.

FreeReviewedSigma · Medium · v5
Product
windows
Service
smbclient-connectivity
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-05
Updated
2026-07-31

What it detects

This rule identifies failed outbound connection attempts from a Windows SMB client to SMB servers, focusing on network connection failures and related SMB session behavior. Attackers commonly probe or attempt exploitation by reaching external SMB services, and repeated failed connection attempts can be an indicator of such activity. It relies on Windows SMB client connectivity event IDs 30803, 30804, and 30806 while filtering out private, loopback, and link-local address ranges using fields such as ServerAddress, Address, and RemoteAddress.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.