What is network-share access?¶
The practical answer¶
Network-share access is the use of a shared folder or storage resource made available across a network.
The key evidential caution¶
The dangerous assumption is that accessing a share proves files were opened, copied or stolen.
It does not.
A share may contain documents, software, backups, configuration or administrative tools.
Access may involve:
Key points¶
- listing the share
- viewing filenames
- opening a file
- copying data
- writing a file
- placing malware
- using scripts or tools stored there
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the share name and path
- source and target systems
- account used
- authentication records
- file and folder activity
- timestamps
- files read, written or created
- related process activity
- subsequent transfer or execution
Legitimate users, backup systems and applications may access shares automatically.
The sequence and purpose therefore matter.
A broad listing followed by selective copying may support collection.
Writing a remote tool to an administrative share may support lateral movement.
Evidential limits¶
Do not assume the account holder personally performed the access.
The account may be shared, compromised or used through an automated process.
Share-access records may be incomplete or retained briefly. Preserve server, endpoint and security-platform evidence promptly, especially where files were written to administrative shares or used to launch later processes.
Also check whether antivirus, backup or indexing services accessed the same share and created similar records.
File-system metadata and endpoint telemetry on the source and target may help distinguish listing, reading, writing and execution.
Operational takeaway¶
Separate listing, reading, writing and copying activity on network shares, and link each action to the source, account and later use.