Detecting SMBv1 Exploitation: Defender for Cloud and Sentinel KQL
Retrospective: this article looks back at events from May 2017, written in 2026 with the benefit of hindsight.
WannaCry and its successors exploited SMB flaws to spread across networks. Even with SMBv1 removed, detecting suspicious SMB activity is a valuable early warning for ransomware and lateral movement.
Signals worth watching
- A single machine connecting to TCP 445 on many other hosts in a short time (scanning).
- Inbound SMB connections from the internet to cloud VMs.
- SMBv1 negotiation on networks where it should be disabled.
- Sudden spikes in file modifications or renames on file shares.
Where the data lives
- Microsoft Defender for Endpoint: network connection and process events on servers and workstations.
- Defender for Cloud: alerts for exposed management and file-sharing ports, plus vulnerability findings.
- Azure network watcher flow logs: connection patterns between subnets.
A starting query
In Defender XDR or Sentinel with Defender data connected, look for hosts connecting to many devices on port 445:
DeviceNetworkEvents
| where RemotePort == 445 and ActionType == "ConnectionSuccess"
| summarize Targets = dcount(RemoteIP) by DeviceName, bin(Timestamp, 10m)
| where Targets > 20
File servers and domain controllers will appear legitimately; add them to an exclusion watchlist.
Response
- Isolate the scanning host with Defender for Endpoint device isolation.
- Check for ransomware indicators: mass file renames, ransom notes, shadow copy deletion.
- Confirm the vulnerability and patch status of hosts it reached.
- Review network segmentation — if a workstation could reach every server, fix that next.
Early detection turns a company-wide ransomware event into a single isolated machine.
- WannaCry (May 2017): SMBv1, Unpatched Servers and What Cloud Teams Missed Incident Teardowns
- How to Disable SMBv1 and Enforce Patch Compliance on Azure VMs How-To & Hardening
- CIO Brief: Why Patch Management Is a Board-Level Issue After WannaCry CIO Briefings