detections
- ID: DT085
- Created: 25th July 2024
- Updated: 23rd October 2025
- Platform: Windows
- MITRE ATT&CK®: DS0024
- Contributor: Ismael Briones-Vilar
Network Registry Key
In Microsoft Windows, when a subject maps a network drive persistently, a key named after the drive letter will appear in the Windows registry location HKEY_CURRENT_USER\Network\. Each subkey under the Network key corresponds to a mapped network drive and contains information about the drive, including the network share path and the username used to connect to it.
Sections
| ID | Name | Description |
|---|---|---|
| IF004.003 | Exfiltration via Personal NAS Device | A subject exfiltrates data using an organization-owned device (such as a laptop) by copying the data from the device to a personal Network Attached Storage (NAS) device, which is attached to a network outside of the control of the organization, such as a home network. Later, using a personal device, the subject accesses the NAS to retrieve the exfiltrated data. |
| PR047.002 | Remote Administrative Services | The subject uses a network-accessible administrative service or operating-system management interface to access resources, transfer content, execute commands, or perform actions on an additional organizational system without establishing an ordinary interactive desktop session.
Methods may include Server Message Block (SMB), Windows administrative shares, Distributed Component Object Model (DCOM), Windows Remote Management (WinRM), or remote Windows Management Instrumentation (WMI). |
MITRE ATT&CK® Mapping (1)
ATT&CK Enterprise Matrix Version 19.1