Skip to content
Security

Event ID 5145: Share object access check

A network share object was checked to see whether client can be granted desired accessSecurity event 5145 logs each file, folder or named pipe accessed through a share, with account, source IP and requested rights. Detailed and noisy.
5145
Event ID
5145
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Network shares
Default logging
Needs configuration

What event 5145 means

Event 5145 is written on the computer hosting the share each time a client opens a file, folder or named pipe through it. Where 5140 says "this account opened the share", 5145 adds RelativeTargetName: the exact object inside the share, plus the requested AccessMask.

This detail makes it one of the best sources for SMB-based lateral movement. Remote service creation shows up as access to the svcctl pipe on IPC$, remote registry as winreg, enumeration as samr, lsarpc or srvsvc, and payload copies as write access to files under ADMIN$ or C$.

Failure events are only produced when access is denied by the share permissions, not by NTFS permissions. Success auditing generates an event per object access, so on file servers and domain controllers (SYSVOL) the volume can be overwhelming; many organizations collect failures only, or success on selected servers.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit Detailed File Share (Success, Failure). Not audited in the default Windows audit policy.

Very high volume on file servers and domain controllers. Microsoft recommends Failure auditing on domain controllers and considering Success only on high-value servers.

Key fields

FieldWhat it tells you
SubjectUserSidSID of the account that requested access.
SubjectUserNameAccount that requested access to the object.
SubjectDomainNameDomain or computer name of the account.
SubjectLogonIdLogon session of the remote user; matches the 4624 network logon on this host.
ObjectTypeAlways File for this event (files, folders and named pipes).
IpAddressIP address of the client.
IpPortSource port of the client connection; 0 for local access.
ShareNameShare used, e.g. \\*\IPC$, \\*\ADMIN$, \\*\C$.
ShareLocalPathLocal path of the share. Empty for IPC$.
RelativeTargetNameObject accessed, relative to the share: a file path such as Temp\payload.exe, a named pipe such as svcctl or samr, or \ for the share root.
AccessMaskRequested access rights as a hexadecimal mask.
ValueMeaning
0x1ReadData (file) or ListDirectory (folder).
0x2WriteData (file) or AddFile (folder).
0x4AppendData (file) or AddSubdirectory (folder).
0x10000DELETE.
0x100000SYNCHRONIZE.
AccessListRequested rights in symbolic form (%%4416 ReadData, %%4417 WriteData, and so on).
AccessReasonFor each requested right, the reason it was granted or denied (the ACE or privilege involved).

Common benign sources

  • Domain members reading Group Policy files under SYSVOL on domain controllers — the largest noise source.
  • Users opening and saving documents on file servers.
  • Management and monitoring tools using IPC$ named pipes (srvsvc, winreg, spoolss) as part of normal operations.

What attackers do that produces it

  • PsExec-style execution: write to a file under ADMIN$ followed by access to the svcctl pipe on IPC$ from the same source IP, then a new service (7045, 4697).
  • Remote registry and credential-related access through the winreg pipe.
  • Domain and host enumeration through the samr, lsarpc and srvsvc pipes (BloodHound/SharpHound, net commands, Impacket tools).
  • Bulk read access to many files on a share by one account in a short period (collection before exfiltration).

Investigation tips

  • Filter on ShareName \\*\IPC$ and list RelativeTargetName values per source IP to see which RPC services were used.
  • For ADMIN$ and C$, look for write access (0x2) to executables or scripts and match file names to service or task creation.
  • Pivot on SubjectLogonId to the 4624 network logon, then to 4672 to see if the session was privileged.
  • Group by account and count distinct RelativeTargetName values to spot mass file access.

MITRE ATT&CK techniques

TechniqueTactics
T1021.002 Remote Services: SMB/Windows Admin SharesLateral Movement
T1570 Lateral Tool TransferLateral Movement
T1135 Network Share DiscoveryDiscovery
T1039 Data from Network Shared DriveCollection

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

17 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 10
  • Medium · 7

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideFile share access: Event IDs 5140 and 5145

Sources and further reading