Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is network-share access?

Network-share access is use of storage made available across a network. A connection to a share does not prove that a file was opened, copied or stolen.

Separate the actions

Preserve the share name and path, source and target, account, authentication, file activity and related processes. Distinguish listing the share, reading a file, writing a file, copying data and executing material stored there.

Server records, source-endpoint telemetry and target filesystem metadata may each show a different part. A broad listing followed by selective copying supports a different conclusion from a background application checking one known path.

Establish purpose and controller

Users, backup, indexing, antivirus and deployment systems can access shares automatically. Compare the sequence with normal activity and authorised work.

Writing a tool to an administrative share and then executing it can support lateral movement; reading selected records before archive creation can support collection. Neither inference should be made from share authentication alone. The account may also be shared or compromised, so connect it to the initiating process and session.

Key takeaway

Report listing, reading, writing, copying and execution separately, linking each supported action to its source, account and later effect.

Reference: CIM-136Cyber Incidents & Offender Methods