About ShareMon

Built from decades of IS/IT audit experience

ShareMon began as an attempt to bring the many separate stages of Windows file-share review into one practical and repeatable workflow.

The background

A recurring audit challenge

I have worked as an IS/IT Audit specialist throughout a career of 38 years, including work for several large organisations.

During that time, I reviewed Windows file-share access control on several occasions. I was repeatedly surprised by how difficult it was to obtain a complete and understandable view of the environment.

There were useful tools for individual parts of the process, but a thorough review normally required information to be gathered from several tools and locations across the Windows environment. The results then had to be combined and interpreted manually.

The practical workflow

A file-share review involves much more than finding shares

Discovering a UNC path is only the beginning. A meaningful review requires an understanding of the systems, credentials, permissions, group relationships and information available through each share.

Targets

Identify what should be scanned

Obtain computer information from Active Directory, distinguish between servers, domain controllers and workstations, and select the relevant targets.

Availability

Determine what can be reached

Check whether systems are available on the network and whether the services required for remote share enumeration are accessible.

Discovery

Enumerate Windows shares

Identify standard, hidden, administrative and published shares using the selected discovery and credential context.

Access context

Understand what the credentials can see

Determine which shares and directories are available to the credentials used and recognise that different credentials may produce different results.

Permissions

Review SMB and NTFS access

Collect share-level permissions, directory permissions and ACL changes below the root where relevant to the review.

Membership

Interpret local and domain groups

Examine local groups, direct user entries and nested Active Directory groups that may broaden the effective access.

Content

Consider what is exposed

Review directory structures, filenames, extensions and selected plaintext content indicators to understand what information may be available.

Assessment

Compare access with intended use

Consider who can reach the information, whether that audience matches the approved access for the share, and whether further investigation is required.

The old result

A large spreadsheet and a difficult review process

After collecting the information, the usual next step was to assemble it into a large static spreadsheet.

The spreadsheet might contain servers, shares, paths, permissions, group details, observations and potential risks. It could support a report to management, but it was time consuming to create and difficult to keep current.

More importantly, the relationship between discovery results, permission information, scan context and supporting evidence was easy to lose.

The start of the project

Could the full workflow be brought into one tool?

After retiring in the spring of 2026, I decided to explore whether the main stages of file-share discovery, inventory, permission collection and analysis could be brought together in one application.

That became the Share Monitoring project, shortened to ShareMon.

The objective is not simply to create another share scanner. ShareMon is intended to preserve the context needed for review: where a share was found, which credentials were used, what permissions were obtained, which scan produced the result and what further analysis was performed.

Development approach

Built and tested in a controlled Windows lab

ShareMon is currently tested in a private lab containing a domain controller, Windows servers and workstations in a test Active Directory environment.

Incremental development

New functionality is added as specific discovery, permission and analysis requirements are identified and tested.

Realistic test scenarios

The lab is used to reproduce broad permissions, nested groups, direct user access, unresolved SIDs and different credential contexts.

Evidence before conclusions

ShareMon records observations and supporting information. Whether access is appropriate still depends on the approved audience and purpose of the individual share.

Pre-release refinement

The project remains under active development. Workflows, interface details, database fields and documentation may change as testing continues.

Project principles

What ShareMon is intended to support

Better visibilityBring share, scan, permission and analysis information into a more coherent view.
Repeatable reviewReduce reliance on one-time commands and manually assembled spreadsheets.
Credential contextPreserve the distinction between representative-user, administrative and Agent results.
Careful interpretationPresent findings for review without claiming that every broad permission is automatically inappropriate.
Practical evidenceRetain logs, result files and scan metadata that help explain how a conclusion was reached.

Explore ShareMon

Learn what the current pre-release version can do

Read the product overview, review the documentation or contact the project about a private evaluation.