Event ID 5145: Share object access check
- Event ID
- 5145
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network shares
- Default logging
- Needs configuration
What event 5145 means
Event 5145 is written on the computer hosting the share each time a client opens a file, folder or named pipe through it. Where 5140 says "this account opened the share", 5145 adds RelativeTargetName: the exact object inside the share, plus the requested AccessMask.
This detail makes it one of the best sources for SMB-based lateral movement. Remote service creation shows up as access to the svcctl pipe on IPC$, remote registry as winreg, enumeration as samr, lsarpc or srvsvc, and payload copies as write access to files under ADMIN$ or C$.
Failure events are only produced when access is denied by the share permissions, not by NTFS permissions. Success auditing generates an event per object access, so on file servers and domain controllers (SYSVOL) the volume can be overwhelming; many organizations collect failures only, or success on selected servers.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit Detailed File Share (Success, Failure). Not audited in the default Windows audit policy.
Very high volume on file servers and domain controllers. Microsoft recommends Failure auditing on domain controllers and considering Success only on high-value servers.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserSid | SID of the account that requested access. | ||||||||||||
| SubjectUserName | Account that requested access to the object. | ||||||||||||
| SubjectDomainName | Domain or computer name of the account. | ||||||||||||
| SubjectLogonId | Logon session of the remote user; matches the 4624 network logon on this host. | ||||||||||||
| ObjectType | Always File for this event (files, folders and named pipes). | ||||||||||||
| IpAddress | IP address of the client. | ||||||||||||
| IpPort | Source port of the client connection; 0 for local access. | ||||||||||||
| ShareName | Share used, e.g. \\*\IPC$, \\*\ADMIN$, \\*\C$. | ||||||||||||
| ShareLocalPath | Local path of the share. Empty for IPC$. | ||||||||||||
| RelativeTargetName | Object accessed, relative to the share: a file path such as Temp\payload.exe, a named pipe such as svcctl or samr, or \ for the share root. | ||||||||||||
| AccessMask | Requested access rights as a hexadecimal mask.
| ||||||||||||
| AccessList | Requested rights in symbolic form (%%4416 ReadData, %%4417 WriteData, and so on). | ||||||||||||
| AccessReason | For each requested right, the reason it was granted or denied (the ACE or privilege involved). |
Common benign sources
- Domain members reading Group Policy files under
SYSVOLon domain controllers — the largest noise source. - Users opening and saving documents on file servers.
- Management and monitoring tools using
IPC$named pipes (srvsvc,winreg,spoolss) as part of normal operations.
What attackers do that produces it
- PsExec-style execution: write to a file under
ADMIN$followed by access to thesvcctlpipe onIPC$from the same source IP, then a new service (7045, 4697). - Remote registry and credential-related access through the
winregpipe. - Domain and host enumeration through the
samr,lsarpcandsrvsvcpipes (BloodHound/SharpHound,netcommands, Impacket tools). - Bulk read access to many files on a share by one account in a short period (collection before exfiltration).
Investigation tips
- Filter on
ShareName\\*\IPC$and listRelativeTargetNamevalues per source IP to see which RPC services were used. - For
ADMIN$andC$, look for write access (0x2) to executables or scripts and match file names to service or task creation. - Pivot on
SubjectLogonIdto the 4624 network logon, then to 4672 to see if the session was privileged. - Group by account and count distinct
RelativeTargetNamevalues to spot mass file access.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
17 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 10
- Medium · 7
- HighDCOM InternetExplorer.Application Iertutil DLL Hijack - SecurityRule by Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), SigmaHQ, DRL 1.1
- HighFirst Time Seen Remote Named PipeRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighImpacket PsExec ExecutionRule by Bhabesh Raj, SigmaHQ, DRL 1.1
- HighPersistence and Execution at Scale via GPO Scheduled TaskRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighPossible Impacket SecretDump Remote ActivityRule by Samir Bousseaden, wagga, SigmaHQ, DRL 1.1
- HighPossible PetitPotam Coerce Authentication AttemptRule by Mauricio Velazco, Michael Haag, SigmaHQ, DRL 1.1
- HighProtected Storage Service AccessRule by Roberto Rodriguez @Cyb3rWard0g, SigmaHQ, DRL 1.1
- HighSMB Create Remote File Admin ShareRule by Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighSuspicious PsExec ExecutionRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- HighT1047 Wmiprvse Wbemcomn DLL HijackRule by Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), SigmaHQ, DRL 1.1
- MediumDCERPC SMB Spoolss Named PipeRule by OTR (Open Threat Research), SigmaHQ, DRL 1.1
- MediumRemote Service Activity via SVCCTL Named PipeRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- MediumRemote Task Creation via ATSVC Named PipeRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- MediumStartup/Logon Script Added to Group Policy ObjectRule by Elastic, Josh Nickels, Marius Rothenbücher, SigmaHQ, DRL 1.1
- MediumSuspicious Access to Sensitive File ExtensionsRule by Samir Bousseaden, SigmaHQ, DRL 1.1
- MediumTransferring Files with Credential Data via Network SharesRule by Teymur Kheirkhabarov, oscd.community, SigmaHQ, DRL 1.1
- MediumWindows Network Access Suspicious desktop.ini ActionRule by Tim Shelton (HAWK.IO), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.