216.73.216.233

T1039: T1039

View on MITRE ATT&CK The MITRE Corporation · Published 31/05/2017 23:30 · Modified 27/03/2026 01:11

Essential information

MITRE technique ID
T1039
Confidence
100/100
Revoked
No
Published
31/05/2017 23:30
Modified
27/03/2026 01:11
Author / Source
The MITRE Corporation

Aliases

Data from Network Shared Drive

Platforms

windows macos linux

Description

Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within [cmd](https://attack.mitre.org/software/S0106) may be used to gather information.

Kill chain phases

Kill chainPhase
mitre-attack collection

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references