Event ID 5142
A network share object was addedA network share object was added. Subject: Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Share Information: Share Name: %5 Share Path: %6
“Share Path” should not point to system directories, such as C:\Windows or C:\, or to critical local folders which contain private or high value information. If the "Share Path" points to these locations it can indicate malicious activity.
Auditing:
Always
Monitor domain controllers and high-value computers for creation of new file shares.
Volume:
Low
This event is logged when a network share is added / created.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"File Share"
Operating Systems:
Windows 7 Windows 2008 R2 Windows 8 Windows 2012 Windows 8.1 Windows 2012 R2 Windows 10 Windows 2016 Windows 2019 Windows 11 Windows 2022Tags:
Audit SuccessCorrelated Events:
4624LEFT/RIGHT arrow keys for navigation
Back to List