Event ID 5140: Network share accessed
- Event ID
- 5140
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network shares
- Default logging
- Needs configuration
What event 5140 means
Event 5140 is written on the computer that hosts the share when a client connects to it. It is generated once per session, on the first access attempt, so it shows which shares a remote account opened rather than every file it touched (that is 5145).
The key fields are SubjectUserName / SubjectDomainName (who), IpAddress / IpPort (from where), ShareName and ShareLocalPath (which share). SubjectLogonId links the access to the network logon (4624 LogonType 3) that created the session.
Administrative shares are the main reason to collect it: ADMIN$ and C$ are used by PsExec-style tools and by attackers copying payloads, and IPC$ is used for named pipes (service control, remote registry, SAMR/LSARPC enumeration). On domain controllers, SYSVOL and NETLOGON accesses by every computer create a lot of noise.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File Share (Success, Failure). Not audited in the default Windows audit policy.
Volume is high on file servers and domain controllers (SYSVOL access by Group Policy) and low on workstations. The same subcategory produces 5142, 5143, 5144 and 5168. A failure 5140 is logged when access is denied at the share level.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserSid | SID of the account that accessed the share. |
| SubjectUserName | Account that accessed the share. Machine accounts (HOST$) are common and usually benign. |
| SubjectDomainName | Domain or computer name of the account. |
| SubjectLogonId | Logon session of the remote user; matches TargetLogonId of the 4624 network logon on this host. |
| ObjectType | Always File for this event. |
| IpAddress | IP address of the client. ::1 or 127.0.0.1 for local access through a UNC path. |
| IpPort | Source port of the client connection. |
| ShareName | Share name in the form \\*\SHARE, e.g. \\*\C$, \\*\ADMIN$, \\*\IPC$, \\*\SYSVOL. |
| ShareLocalPath | Local path of the share, e.g. \??\C:\Windows for ADMIN$. Empty for IPC$. |
| AccessMask | Requested access rights. For 5140 this is normally 0x1 (ReadData / ListDirectory). |
| AccessList | Access rights in symbolic form, e.g. %%4416 (ReadData or ListDirectory). |
Common benign sources
- Workstations and servers reading
SYSVOLandNETLOGONon domain controllers for Group Policy and logon scripts. - Users mapping departmental shares and home drives.
- Management and backup tools, software deployment and inventory agents connecting to
ADMIN$,C$orIPC$.
What attackers do that produces it
- Lateral movement with PsExec, Impacket
smbexec/psexecor similar tools: anADMIN$orIPC$access from a workstation, followed by a service installation (7045, 4697). - Staging or retrieving files through
C$on a remote host with stolen credentials. - Share and user enumeration over
IPC$(SAMR, LSARPC, SRVSVC named pipes) from a host that does not normally query this server. - Collection of data from file servers by an account that rarely touches them.
Investigation tips
- Filter out machine accounts and
SYSVOL/NETLOGON, then reviewADMIN$,C$and other admin shares by source IP and account. - Pivot on
SubjectLogonIdto the 4624 LogonType 3 on the same host to confirm the authentication package (NTLM vs Kerberos). - If Detailed File Share is enabled, check 5145 for the files and named pipes used in the same session (
svcctl,samr,lsarpc,srvsvc). - On the source host, look for the matching outbound connection (Sysmon 3, 5156) and the tool that initiated it.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowAccess To ADMIN$ Network ShareRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.