Zeek SMB File Access to Sensitive Email/Database/Backup Extensions

Alerts on Zeek-observed SMB file accesses to filenames ending with high-value sensitive extensions.

FreeReviewedSigma · Medium · v2
Product
zeek
Service
smb_files
Author
Samir Bousseaden, @neu5ron (SigmaHQ), DRL 1.1
Published
2020-04-02
Updated
2026-07-31

What it detects

This rule flags SMB file accesses in Zeek logs where the accessed filename ends with a set of sensitive or high-value extensions (e.g., PST/OST/MSG, EDB/NSF, backup and dump files). Attackers often use file discovery and collection to gather sensitive data such as mailboxes, credentials-related artifacts, databases, and system dumps. The detection relies on Zeek SMB file event telemetry that includes the accessed file name and supports suffix matching.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.