Event ID 5142: Network share added
- Event ID
- 5142
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network shares
- Default logging
- Needs configuration
What event 5142 means
Event 5142 is written on the computer where a new share is created, whether through Explorer, net share, New-SmbShare, WMI or a remote API call. It records the account (SubjectUserName, SubjectLogonId), the share name and the local folder it exposes.
New shares are infrequent on most servers and rare on workstations, so this event is easy to review. A share created on a workstation, pointing to a whole drive, or pointing to a temp or user-profile folder is a reason to look closer.
Attackers create shares to stage data for exfiltration, to move tools between hosts, or to expose a drive for later access. Ransomware operators sometimes share drives to spread encryption across the network.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File Share (Success). Not audited in the default Windows audit policy.
Share changes and deletions are logged by the same subcategory as 5143 and 5144.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserSid | SID of the account that created the share. |
| SubjectUserName | Account that created the share. |
| SubjectDomainName | Domain or computer name of the account. |
| SubjectLogonId | Logon session that created the share; pivot to 4624 to learn whether it was local or remote. |
| ShareName | New share name in the form \\*\NAME. A trailing $ hides it from casual browsing. |
| ShareLocalPath | Folder exposed by the share, e.g. C:\Data. A drive root (C:\) or a folder under Temp, AppData or ProgramData is unusual. |
Common benign sources
- Administrators creating departmental or project shares on file servers.
- Server roles and applications creating their shares during installation (e.g. print, deployment and backup software).
- Users sharing a folder from their workstation where policy allows it.
What attackers do that produces it
- Creating a share over a staging directory to collect data from many hosts before exfiltration.
- Sharing a full drive (
net share x=C:\ /grant:everyone,full) to give remote access to the whole disk. - Creating a share to distribute tools or ransomware payloads to other machines.
Investigation tips
- Check whether the share was created by a user or by
SYSTEMand which process ran (net.exe,powershell.exein 4688 or Sysmon 1). - Review the share permissions on the live host (
Get-SmbShare,Get-SmbShareAccess);Everyonewith full control is a red flag. - Look for 5140 events on the new share afterwards to see who connected to it and from where.
- Check for a matching 5144 later, which may indicate cleanup after use.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.