Windows SMB Client Security: Rejected Guest Logon with Blank UserName

Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.

FreeReviewedSigma · Medium · v2
Product
windows
Service
smbclient-security
Author
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w (SigmaHQ), DRL 1.1
Published
2021-06-30
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows SMB client security events indicating a rejected logon attempt where the UserName field is empty (guest-like) and the ServerName starts with a backslash-prefixed pattern. Attackers may probe SMB endpoints using atypical or unauthenticated guest patterns to elicit responses or set up follow-on access attempts. It relies on Event ID 31017 telemetry from the Windows SMB client security log, including UserName and ServerName fields.

Related detections4 linkedT1110.001 — drag to rearrange
Suspicious Bruteforce via Password Reset (via security)
Suspicious sshpass Noninteractive SSH Password Authentication (via process_creation)
Windows PowerShell Credential Guessing via LDAP using System.Net.NetworkCredential
Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Pivot detection · T1110.001 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.