Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Remote connection to an administrative share by a user account

Covers the share-access leg of AN1468: a network connection to the hidden ADMIN$ or C$ share, which is how an operator stages a binary or reaches the service control and task scheduler paths on a remote host. The analytic's ShareName knob has no corresponding field on 4624 or 4648, so the leg is taken from EventID 5140 on the same Security channel, where the share name is actually recorded; the second leg — remote service creation or process execution within a TimeWindow of the access — is a cross-event join Sigma cannot express and must be pivoted to by hand. Machine accounts are excluded because software-deployment and management agents running as SYSTEM generate nearly all benign ADMIN$ traffic, and that exclusion is a known bypass: an NTLM relay or coercion chain arrives as a computer account and will not alert. Both share-access events are off by default and must be turned on first — 5140 needs the *Audit File Share* subcategory, and 5145, which additionally records the file within the share, needs *Audit Detailed File Share* and is far higher volume. Neither is enabled by a clean install or by the Microsoft and CIS baselines, so an empty result means blind rather than quiet. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0530, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Remote connection to an administrative share by a user accountid: a1916bf9-a5ef-4599-99fc-631ce7376f7astatus: experimentaldescription: |  Covers the share-access leg of AN1468: a network connection to the hidden  ADMIN$ or C$ share, which is how an operator stages a binary or reaches the  service control and task scheduler paths on a remote host. The analytic's  ShareName knob has no corresponding field on 4624 or 4648, so the leg is taken  from EventID 5140 on the same Security channel, where the share name is  actually recorded; the second leg — remote service creation or process  execution within a TimeWindow of the access — is a cross-event join Sigma  cannot express and must be pivoted to by hand. Machine accounts are excluded  because software-deployment and management agents running as SYSTEM generate  nearly all benign ADMIN$ traffic, and that exclusion is a known bypass: an  NTLM relay or coercion chain arrives as a computer account and will not alert.  Both share-access events are off by default and must be turned on first — 5140  needs the *Audit File Share* subcategory, and 5145, which additionally records  the file within the share, needs *Audit Detailed File Share* and is far higher  volume. Neither is enabled by a clean install or by the Microsoft and CIS  baselines, so an empty result means blind rather than quiet.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0530, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1021/002  - https://attack.mitre.org/detectionstrategies/DET0530author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.lateral-movement  - attack.t1021.002logsource:  product: windows  service: securitydetection:  selection_share:    EventID: 5140    ShareName|endswith:      - '\ADMIN$'      - '\C$'  filter_machine_accounts:    SubjectUserName|endswith: '$'  condition: selection_share and not filter_machine_accountsfalsepositives:  - "Software deployment and configuration management run under a named service account rather than SYSTEM. Client push installation, patching and remote script agents connect to ADMIN$ on every managed host, which is the largest benign source that the machine-account exclusion does not remove."  - "Backup, inventory and vulnerability scanning tools that mount C$ across the estate on a fixed schedule, producing a broad fan-out of accesses from one or two service identities."  - "Helpdesk and administrator activity that is genuinely remote file copy or remote registry work. Nothing in 5140 separates an operator staging a payload from an administrator fixing a machine, which is why MITRE's UserContext knob — rare or first-time access by a given account — carries most of the discrimination in practice."  - "Backup or imaging software that impersonates an interactive administrator, and clustered or replicated file services that reach C$ on their partners as part of normal operation."level: medium

Sentinel · KQL

Run this as a search.

SecurityEvent| where ((EventID == 5140 and (ShareName endswith "\\ADMIN$" or ShareName endswith "\\C$")) and not (SubjectUserName endswith "$"))

Splunk · SPL

Run this as a search.

index=* ((EventID="5140" AND (ShareName="*\\ADMIN$" OR ShareName="*\\C$")) AND NOT (SubjectUserName="*$"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE ((event.code == 5140 AND (TO_LOWER(winlog.event_data.ShareName) LIKE "*\\\\admin$" OR TO_LOWER(winlog.event_data.ShareName) LIKE "*\\\\c$")) AND NOT (TO_LOWER(user.name) LIKE "*$"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="7">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="EventID" type="pcre2">(?i)^5140$</field>    <field name="ShareName" type="pcre2">(?i)(\\ADMIN\$$|\\C\$$)</field>    <field name="SubjectUserName" negate="yes" type="pcre2">(?i)\$$</field>    <description>Remote connection to an administrative share by a user account</description>    <mitre>      <id>T1021.002</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.