<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SMB - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/smb/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 07:05:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/smb/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Unauthorized SMB Traffic to the Internet</title><link>https://feed.craftedsignal.io/briefs/2026-08-smb-internet-egress/</link><pubDate>Mon, 31 Aug 2026 07:05:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-smb-internet-egress/</guid><description>This brief documents the risks and detection strategies for internal Windows SMB (TCP 139/445) traffic traversing the network perimeter, a common indicator of unauthorized remote access or data exfiltration.</description><content:encoded><![CDATA[<p>SMB (Server Message Block) is a protocol designed for local resource sharing, such as files and printers, within trusted network segments. Exposing SMB directly to the Internet significantly increases the attack surface, as threat actors frequently target this protocol to establish backdoors, gain initial access, or exfiltrate sensitive data.</p>
<p>Defenders should treat any observed outbound SMB traffic originating from internal IP ranges to external, non-private destinations as a high-fidelity indicator of potential compromise. Such activity often suggests that an internal host has been infected with malware, is participating in a C2 channel, or is being used to stage data for exfiltration. Organizations should ensure that firewalls explicitly block TCP ports 139 and 445 at the network egress point to prevent accidental or malicious exposure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation or misuse of SMB over the internet can lead to unauthorized remote code execution, unauthorized access to sensitive file shares, and large-scale data exfiltration. If an internal system initiates SMB traffic to an external attacker-controlled server, it may result in the full compromise of that system and provide the attacker with a persistent foothold for lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement strict egress filtering on all perimeter firewalls to block TCP 139 and 445 to the public internet.</li>
<li>Deploy the provided detection logic to identify internal systems attempting to communicate over SMB to external IP addresses.</li>
<li>Investigate any alerts generated by this logic by reviewing the source system for malware or indicators of unauthorized access.</li>
<li>Review network configurations to identify and remediate any misconfigured devices that might be routing SMB traffic to the internet.</li>
<li>Exclude verified legitimate services, such as cloud-based backup solutions or site-to-site VPNs, from the detection alerts by adding their IP ranges to your environment's allowlist.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>initial-access</category><category>exfiltration</category><category>network</category><category>smb</category></item></channel></rss>