diff --git a/evtx/Maps/Microsoft-Windows-SmbClient-Security_Microsoft-Windows-SMBClient_31010.map b/evtx/Maps/Microsoft-Windows-SmbClient-Security_Microsoft-Windows-SMBClient_31010.map new file mode 100644 index 00000000..1307073b --- /dev/null +++ b/evtx/Maps/Microsoft-Windows-SmbClient-Security_Microsoft-Windows-SMBClient_31010.map @@ -0,0 +1,58 @@ +Author: Paul Elliott +Description: The SMB client failed to connect to the share +EventId: 31010 +Channel: "Microsoft-Windows-SmbClient/Security" +Provider: Microsoft-Windows-SMBClient +Maps: + - + Property: PayloadData1 + PropertyValue: "Share Name: %ShareName%" + Values: + - + Name: ShareName + Value: "/Event/EventData/Data[@Name=\"ShareName\"]" + - + Property: PayloadData2 + PropertyValue: "Reason: %Reason%" + Values: + - + Name: Reason + Value: "/Event/EventData/Data[@Name=\"Reason\"]" + +Lookups: + - + Name: Reason + Default: Unknown code + Values: + 12: Access Denied. + +# Documentation: +# +# +# Example Event Data: +# +# +# +# 31010 +# 0 +# 2 +# 0 +# 0 +# 0x200000000000100 +# +# 123456 +# +# +# Microsoft-Windows-SmbClient/Security +# machine.domain.tld +# +# +# +# 12 +# 3221225506 +# 17 +# \fileserver\share +# 0 +# +# +#