Skip to content

Latest commit

 

History

History
15 lines (10 loc) · 666 Bytes

Data_from_network_shared_drive.md

File metadata and controls

15 lines (10 loc) · 666 Bytes

Data from Network Shared Drive

MITRE ATT&CK technique T1039

Tactic: Collection

Platform: Windows, Linux, Mac

Deception Techniques

  • Create fake network shares, or create fake directories/files (i.e. honeyfiles) in real network shares, and monitor access to them using the OS file/folder auditing or FIM tools.
  • Create decoy files or documents (beacons) that phone home when opened.

Useful Tools

  • honeyλ - Serverless application designed to create and monitor URL honeytokens (i.e. fake HTTP endpoints) automatically
  • canarytokens