DragonForce Locker SMB Share Enumeration via NetShareEnum (T1135)
Detects DragonForce ransomware attempting to identify accessible SMB network shares by executing 'net view' commands. This activity is a precursor to encrypting files on reachable administrative shares (e.g., C$) while excluding system-specific shares like ADMIN$.
Cortex XDR

