MITRE ATT&CK

Windows Admin Shares (e.g., C$, ADMIN$, IPC$) are built-in network shares that allow administrators to remotely manage systems via the SMB protocol. Although these shares are enabled by default for legitimate administrative tasks, adversaries abuse them to move laterally, stage payloads, and execute remote commands.


How Attackers Use It


Detection

Important Windows Event Logs

Important Sysmon Event IDs

Screenshot 2025-02-27 224743.png