Skip to content
Security

Event ID 5140: Network share accessed

A network share object was accessedSecurity event 5140 logs the first access to a network share in an SMB session: account, source IP and share name. Key for tracking C$, ADMIN$ and IPC$ use.
5140
Event ID
5140
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Network shares
Default logging
Needs configuration

What event 5140 means

Event 5140 is written on the computer that hosts the share when a client connects to it. It is generated once per session, on the first access attempt, so it shows which shares a remote account opened rather than every file it touched (that is 5145).

The key fields are SubjectUserName / SubjectDomainName (who), IpAddress / IpPort (from where), ShareName and ShareLocalPath (which share). SubjectLogonId links the access to the network logon (4624 LogonType 3) that created the session.

Administrative shares are the main reason to collect it: ADMIN$ and C$ are used by PsExec-style tools and by attackers copying payloads, and IPC$ is used for named pipes (service control, remote registry, SAMR/LSARPC enumeration). On domain controllers, SYSVOL and NETLOGON accesses by every computer create a lot of noise.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File Share (Success, Failure). Not audited in the default Windows audit policy.

Volume is high on file servers and domain controllers (SYSVOL access by Group Policy) and low on workstations. The same subcategory produces 5142, 5143, 5144 and 5168. A failure 5140 is logged when access is denied at the share level.

Key fields

FieldWhat it tells you
SubjectUserSidSID of the account that accessed the share.
SubjectUserNameAccount that accessed the share. Machine accounts (HOST$) are common and usually benign.
SubjectDomainNameDomain or computer name of the account.
SubjectLogonIdLogon session of the remote user; matches TargetLogonId of the 4624 network logon on this host.
ObjectTypeAlways File for this event.
IpAddressIP address of the client. ::1 or 127.0.0.1 for local access through a UNC path.
IpPortSource port of the client connection.
ShareNameShare name in the form \\*\SHARE, e.g. \\*\C$, \\*\ADMIN$, \\*\IPC$, \\*\SYSVOL.
ShareLocalPathLocal path of the share, e.g. \??\C:\Windows for ADMIN$. Empty for IPC$.
AccessMaskRequested access rights. For 5140 this is normally 0x1 (ReadData / ListDirectory).
AccessListAccess rights in symbolic form, e.g. %%4416 (ReadData or ListDirectory).

Common benign sources

  • Workstations and servers reading SYSVOL and NETLOGON on domain controllers for Group Policy and logon scripts.
  • Users mapping departmental shares and home drives.
  • Management and backup tools, software deployment and inventory agents connecting to ADMIN$, C$ or IPC$.

What attackers do that produces it

  • Lateral movement with PsExec, Impacket smbexec/psexec or similar tools: an ADMIN$ or IPC$ access from a workstation, followed by a service installation (7045, 4697).
  • Staging or retrieving files through C$ on a remote host with stolen credentials.
  • Share and user enumeration over IPC$ (SAMR, LSARPC, SRVSVC named pipes) from a host that does not normally query this server.
  • Collection of data from file servers by an account that rarely touches them.

Investigation tips

  • Filter out machine accounts and SYSVOL/NETLOGON, then review ADMIN$, C$ and other admin shares by source IP and account.
  • Pivot on SubjectLogonId to the 4624 LogonType 3 on the same host to confirm the authentication package (NTLM vs Kerberos).
  • If Detailed File Share is enabled, check 5145 for the files and named pipes used in the same session (svcctl, samr, lsarpc, srvsvc).
  • On the source host, look for the matching outbound connection (Sysmon 3, 5156) and the tool that initiated it.

MITRE ATT&CK techniques

TechniqueTactics
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement
T1135 Network Share DiscoveryDiscovery
T1039 Data from Network Shared DriveCollection
T1570 Lateral Tool TransferLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideFile share access: Event IDs 5140 and 5145

Sources and further reading