Windows SMB Server Share Connection Without Signing or Encryption

Alert on SMB share connections (IPC$/ADMIN$/C$) where signing and encryption are both reported as disabled.

FreeReviewedSigma · Medium · v2
Product
windows
Service
smbserver-connectivity
Author
Mohamed Abdelghani (SigmaHQ), DRL 1.1
Published
2025-10-19
Updated
2026-07-31

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags SMB server connections to specific shares where message signing is not used and encryption is not enabled. Such unsecured SMB sessions can make it easier for an attacker to access administrative or interprocess shares and perform lateral movement or other follow-on activity. It relies on Windows SMB server connectivity events (EventID 4000) containing share name, signing status, encryption status, and client address fields for local/IP filtering.

Related detections9 linkedT1021.002 — drag to rearrange
Suspicious Ransomware Fan-Out Deployment via PsExec Spread (Qilin)
Suspicious Impacket smbexec Command Execution Pattern
Malicious Impacket Wmiexec Remote Command Execution Pattern
Suspicious Remote Admin Share Execution via Conhost
Malicious Network Share Manipulation via Commandline (via process_creation)
Suspicious Number of Oustanding SMB Requests Increased (via process_creation)
Suspicious SMB Insecure Guest Authentication Activated - Native (via security)
Suspicious PSexec Execution Over SMB Share (via security)
Suspicious Permissions Modification on a Network Share (via security)
Windows SMB Server Share Connection Without Signing or Encryption
Pivot detection · T1021.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.