Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1021.002

T1021.002SMB/Windows Admin Shares

T1021.002 — SMB/Windows Admin Shares is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 15 detection use cases covering it and 134 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
134Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Remote service execution — PsExec / SMB lateral movement Internal actions · alerting DSΣP Detect PsExec With accepteula Flag ESCU actions · alerting P Executable File Written in Administrative SMB Share ESCU actions · alerting P Impacket Lateral Movement Commandline Parameters ESCU actions · alerting P Impacket Lateral Movement smbexec CommandLine Parameters ESCU actions · alerting P Impacket Lateral Movement WMIExec Commandline Parameters ESCU actions · alerting P Windows PUA Named Pipe ESCU actions · hunting P Windows RMM Named Pipe ESCU actions · hunting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P Windows Suspicious C2 Named Pipe ESCU actions · alerting P Windows Suspicious Named Pipe ESCU actions · alerting P Windows Theme File Creation in Unusual Location ESCU actions · hunting P SMB Traffic Spike ESCU actions · hunting P SMB Traffic Spike - MLTK ESCU actions · hunting P [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) Bespoke install · alerting DSΣP

Articles citing this technique (134)