Skip to content
Security

Event ID 5142: Network share added

A network share object was addedSecurity event 5142 records a new network share: who created it, its name and local path. Watch for shares exposing drives or staging folders.
5142
Event ID
5142
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Network shares
Default logging
Needs configuration

What event 5142 means

Event 5142 is written on the computer where a new share is created, whether through Explorer, net share, New-SmbShare, WMI or a remote API call. It records the account (SubjectUserName, SubjectLogonId), the share name and the local folder it exposes.

New shares are infrequent on most servers and rare on workstations, so this event is easy to review. A share created on a workstation, pointing to a whole drive, or pointing to a temp or user-profile folder is a reason to look closer.

Attackers create shares to stage data for exfiltration, to move tools between hosts, or to expose a drive for later access. Ransomware operators sometimes share drives to spread encryption across the network.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File Share (Success). Not audited in the default Windows audit policy.

Share changes and deletions are logged by the same subcategory as 5143 and 5144.

Key fields

FieldWhat it tells you
SubjectUserSidSID of the account that created the share.
SubjectUserNameAccount that created the share.
SubjectDomainNameDomain or computer name of the account.
SubjectLogonIdLogon session that created the share; pivot to 4624 to learn whether it was local or remote.
ShareNameNew share name in the form \\*\NAME. A trailing $ hides it from casual browsing.
ShareLocalPathFolder exposed by the share, e.g. C:\Data. A drive root (C:\) or a folder under Temp, AppData or ProgramData is unusual.

Common benign sources

  • Administrators creating departmental or project shares on file servers.
  • Server roles and applications creating their shares during installation (e.g. print, deployment and backup software).
  • Users sharing a folder from their workstation where policy allows it.

What attackers do that produces it

  • Creating a share over a staging directory to collect data from many hosts before exfiltration.
  • Sharing a full drive (net share x=C:\ /grant:everyone,full) to give remote access to the whole disk.
  • Creating a share to distribute tools or ransomware payloads to other machines.

Investigation tips

  • Check whether the share was created by a user or by SYSTEM and which process ran (net.exe, powershell.exe in 4688 or Sysmon 1).
  • Review the share permissions on the live host (Get-SmbShare, Get-SmbShareAccess); Everyone with full control is a red flag.
  • Look for 5140 events on the new share afterwards to see who connected to it and from where.
  • Check for a matching 5144 later, which may indicate cleanup after use.

MITRE ATT&CK techniques

TechniqueTactics
T1074 Data StagedCollection
T1039 Data from Network Shared DriveCollection
T1570 Lateral Tool TransferLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading