Detection rules › By eventMicrosoft-Windows-Security-Auditing event 51403 detection rules reference this event. View event page.Sigma (1)Access To ADMIN$ Network Share severity low T1021.002 Splunk (2)Network Share Discovery Via Dir Command T1135 Windows Administrative Shares Accessed On Multiple Hosts T1135