{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/monitoring/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["medium"],"_cs_tags":["insider-threat","data-exfiltration","windows","monitoring"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThis detection analytic identifies suspicious file activity within Windows environments, focusing on administrative network shares (Admin$, C$, and IPC$). By analyzing Windows Security Event Log 5145, the analytic tracks write and append operations on common file types, including documents, archives, and logs. This mechanism is designed to detect insider threats, unauthorized data staging, or exfiltration attempts, as well as potential data sabotage.\u003c/p\u003e\n\u003cp\u003eThe detection logic functions by establishing a baseline for file-write volume per user and destination host. It flags instances where write activity exceeds three standard deviations from the user's historical average or crosses a defined threshold of 20 events within a 5-minute window. This approach helps filter out routine, authorized network traffic while highlighting anomalous batch-processing or manual mass-copying behaviors often associated with malicious intent or compromised credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of the behaviors monitored by this analytic could lead to unauthorized access, massive data exfiltration, or the deletion of evidence by an insider or an attacker who has moved laterally within the network. This activity has been observed in the context of information sabotage and has been linked to potential exfiltration phases for ransomware campaigns.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Windows Security Event Log 5145 (Object Access) via Group Policy on all endpoints serving as network shares.\u003c/li\u003e\n\u003cli\u003eEnsure Windows Security Event Logs are being forwarded and ingested into the SIEM.\u003c/li\u003e\n\u003cli\u003eDeploy the detection logic provided in the SIEM to baseline user behavior and tune the thresholds (e.g., the 20-event limit) based on the organization's normal file-sharing volume.\u003c/li\u003e\n\u003cli\u003eInvestigate alerts flagged by this logic by reviewing the source user and source IP associated with the anomalous write volume.\u003c/li\u003e\n\u003cli\u003eCross-reference detected alerts with user access logs to determine if the activity is aligned with the user's job role and typical workstation behavior.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T21:12:12Z","date_published":"2026-08-05T21:12:12Z","id":"https://feed.craftedsignal.io/briefs/2026-08-high-frequency-network-share-copy/","summary":"An anomaly-based detection analytic identifying potential insider threats or data exfiltration by monitoring for high-frequency write operations to administrative network shares via Windows Event ID 5145.","title":"Detection of High-Frequency File Operations in Administrative Network Shares","url":"https://feed.craftedsignal.io/briefs/2026-08-high-frequency-network-share-copy/"}],"language":"en","title":"CraftedSignal Threat Feed - Monitoring","version":"https://jsonfeed.org/version/1.1"}