AI-Assisted Rapid SMB Share Discovery via Mass Host Targeting (T1135)
This rule detects potential internal network reconnaissance activities by monitoring for either mass execution of network discovery commands (such as 'net view' or 'net share') targeting multiple unique hosts within a 5-minute window, or by monitoring for mass outbound network connections to port 445 (SMB) across multiple unique destination hosts within the same timeframe. This behavior is indicative of an attacker attempting to map available network shares or identify reachable systems for lateral movement.
Splunk (SPL)

