Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT085
  • Created: 25th July 2024
  • Updated: 23rd October 2025
  • Platform: Windows
  • MITRE ATT&CK®: DS0024
  • Contributor: Ismael Briones-Vilar

Network Registry Key

In Microsoft Windows, when a subject maps a network drive persistently, a key named after the drive letter will appear in the Windows registry location HKEY_CURRENT_USER\Network\.  Each subkey under the Network key corresponds to a mapped network drive and contains information about the drive, including the network share path and the username used to connect to it.

Sections

ID Name Description
IF004.003Exfiltration via Personal NAS Device

A subject exfiltrates data using an organization-owned device (such as a laptop) by copying the data from the device to a personal Network Attached Storage (NAS) device, which is attached to a network outside of the control of the organization, such as a home network. Later, using a personal device, the subject accesses the NAS to retrieve the exfiltrated data.

PR047.002Remote Administrative Services

The subject uses a network-accessible administrative service or operating-system management interface to access resources, transfer content, execute commands, or perform actions on an additional organizational system without establishing an ordinary interactive desktop session.

 

Methods may include Server Message Block (SMB), Windows administrative shares, Distributed Component Object Model (DCOM), Windows Remote Management (WinRM), or remote Windows Management Instrumentation (WMI).