Event ID 5142
A network share object was addedA network share object was added.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Share Information:
Share Name: %5
Share Path: %6“Share Path” should not point to system directories, such as C:\Windows or C:\, or to critical local folders which contain private or high value information. If the "Share Path" points to these locations it can indicate malicious activity.
Auditing: Always
Monitor domain controllers and high-value computers for creation of new file shares.
Volume: Low
This event is logged when a network share is added / created.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"File Share" Operating Systems:
Windows VistaWindows 2008Windows 2008 R2Windows 7Windows 2012Windows 2012 R2Windows 8Windows 8.1Windows 10Windows 11Windows 2016Windows 2019Windows 2022Windows 2025Tags:
Audit SuccessCorrelated Events:
4624LEFT/RIGHT arrow keys for navigation
Back to List