Detection: Windows File Share Discovery With Powerview


The following analytic identifies the use of the Invoke-ShareFinder PowerShell commandlet part of PowerView. This module obtains the list of all active domain computers and lists the active shares on each computer. Network file shares in Active Directory environments may contain sensitive information like backups, scripts, credentials, etc. Adversaries who have obtained a foothold in an AD network may leverage PowerView to identify secrets and leverage them for Privilege Escalation or Lateral Movement.


No annotations available.


To successfully implement this analytic, you will need to enable PowerShell Script Block Logging on some or all endpoints. Additional setup here

Known False Positives


Associated Analytic Story

Risk Based Analytics (RBA)

Risk Message Risk Score Impact Confidence
Invoke-ShareFinder commandlet was executed on $Computer$ 48 60 80
The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author.


Version: 4