T1021.002SMB/Windows Admin Shares
T1021.002 — SMB/Windows Admin Shares is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 15 detection use cases covering it and 134 threat-intel articles citing it.
Lateral Movement
15Use cases
134Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1021 · Remote Services
Use cases covering this technique (15)
Remote service execution — PsExec / SMB lateral movement Detect PsExec With accepteula Flag Executable File Written in Administrative SMB Share Impacket Lateral Movement Commandline Parameters Impacket Lateral Movement smbexec CommandLine Parameters Impacket Lateral Movement WMIExec Commandline Parameters Windows PUA Named Pipe Windows RMM Named Pipe Windows Special Privileged Logon On Multiple Hosts Windows Suspicious C2 Named Pipe Windows Suspicious Named Pipe Windows Theme File Creation in Unusual Location SMB Traffic Spike SMB Traffic Spike - MLTK [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025)Articles citing this technique (134)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high A tale of two eras art-40
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit CISA KEV: CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability art-111
crit Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection art-178
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
crit ESET Threat Report H2 2025 art-647
crit CISA KEV: CVE-2025-55182 — Meta React Server Components Remote Code Execution Vulnerability art-670
high In memoriam: David Harley art-713
crit CISA KEV: CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability art-742
crit CISA KEV: CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability art-844
crit CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability art-848
crit CISA KEV: CVE-2025-24472 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-956
crit CISA KEV: CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability art-998
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1032
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1051
crit CISA KEV: CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability art-1054
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1089
crit CISA KEV: CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability art-1115