{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/smb/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SMB"],"_cs_severities":["medium"],"_cs_tags":["initial-access","exfiltration","network","smb"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eSMB (Server Message Block) is a protocol designed for local resource sharing, such as files and printers, within trusted network segments. Exposing SMB directly to the Internet significantly increases the attack surface, as threat actors frequently target this protocol to establish backdoors, gain initial access, or exfiltrate sensitive data.\u003c/p\u003e\n\u003cp\u003eDefenders should treat any observed outbound SMB traffic originating from internal IP ranges to external, non-private destinations as a high-fidelity indicator of potential compromise. Such activity often suggests that an internal host has been infected with malware, is participating in a C2 channel, or is being used to stage data for exfiltration. Organizations should ensure that firewalls explicitly block TCP ports 139 and 445 at the network egress point to prevent accidental or malicious exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation or misuse of SMB over the internet can lead to unauthorized remote code execution, unauthorized access to sensitive file shares, and large-scale data exfiltration. If an internal system initiates SMB traffic to an external attacker-controlled server, it may result in the full compromise of that system and provide the attacker with a persistent foothold for lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict egress filtering on all perimeter firewalls to block TCP 139 and 445 to the public internet.\u003c/li\u003e\n\u003cli\u003eDeploy the provided detection logic to identify internal systems attempting to communicate over SMB to external IP addresses.\u003c/li\u003e\n\u003cli\u003eInvestigate any alerts generated by this logic by reviewing the source system for malware or indicators of unauthorized access.\u003c/li\u003e\n\u003cli\u003eReview network configurations to identify and remediate any misconfigured devices that might be routing SMB traffic to the internet.\u003c/li\u003e\n\u003cli\u003eExclude verified legitimate services, such as cloud-based backup solutions or site-to-site VPNs, from the detection alerts by adding their IP ranges to your environment's allowlist.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T07:05:50Z","date_published":"2026-08-31T07:05:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-smb-internet-egress/","summary":"This brief documents the risks and detection strategies for internal Windows SMB (TCP 139/445) traffic traversing the network perimeter, a common indicator of unauthorized remote access or data exfiltration.","title":"Detection of Unauthorized SMB Traffic to the Internet","url":"https://feed.craftedsignal.io/briefs/2026-08-smb-internet-egress/"}],"language":"en","title":"CraftedSignal Threat Feed - SMB","version":"https://jsonfeed.org/version/1.1"}