SMB Forensics
Audit Logs
Forensics:


Ways to access file share:
Explorer.exe:

PowerShell/CMD:

Enumerating:

Enumeration Priv Denied:

Resource Access Denied:

EventIDs:


MISC:

Last updated