logo

Threat Hunting With Python Part 3: Taming SMB

ID: 2a5f2147-1273-5ee4-ac4f-339fd7da5bfe

STIX ID: report--2a5f2147-1273-5ee4-ac4f-339fd7da5bfe

Feed Name: Dragos Blog

Date Published: 2018-01-30

Date Updated: 2026-04-27

...
...

This third entry in a Python-based threat hunting series examines SMB/CIFS in industrial control networks, recounting how ETERNALBLUE-enabled ransomware (WannaCry, Petya/NotPetya, Bad Rabbit) spread and demonstrating how to hunt SMB authentication activity using Bro/Zeek NTLM logs and Python/pandas to spot risky cross-subnet pivots and misuse of privileged accounts. It walks through a lab simulating corporate and PCN subnets, emphasizes leveraging vendor guidance (e.g., Honeywell EPKS) for expected behaviors, and recommends controls such as blocking SMB between business and PCN to limit lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.