Targets
Identify what should be scanned
Obtain computer information from Active Directory, distinguish between servers, domain controllers and workstations, and select the relevant targets.
About ShareMon
ShareMon began as an attempt to bring the many separate stages of Windows file-share review into one practical and repeatable workflow.
The background
I have worked as an IS/IT Audit specialist throughout a career of 38 years, including work for several large organisations.
During that time, I reviewed Windows file-share access control on several occasions. I was repeatedly surprised by how difficult it was to obtain a complete and understandable view of the environment.
There were useful tools for individual parts of the process, but a thorough review normally required information to be gathered from several tools and locations across the Windows environment. The results then had to be combined and interpreted manually.
The practical workflow
Discovering a UNC path is only the beginning. A meaningful review requires an understanding of the systems, credentials, permissions, group relationships and information available through each share.
Targets
Obtain computer information from Active Directory, distinguish between servers, domain controllers and workstations, and select the relevant targets.
Availability
Check whether systems are available on the network and whether the services required for remote share enumeration are accessible.
Discovery
Identify standard, hidden, administrative and published shares using the selected discovery and credential context.
Access context
Determine which shares and directories are available to the credentials used and recognise that different credentials may produce different results.
Permissions
Collect share-level permissions, directory permissions and ACL changes below the root where relevant to the review.
Membership
Examine local groups, direct user entries and nested Active Directory groups that may broaden the effective access.
Content
Review directory structures, filenames, extensions and selected plaintext content indicators to understand what information may be available.
Assessment
Consider who can reach the information, whether that audience matches the approved access for the share, and whether further investigation is required.
The old result
After collecting the information, the usual next step was to assemble it into a large static spreadsheet.
The spreadsheet might contain servers, shares, paths, permissions, group details, observations and potential risks. It could support a report to management, but it was time consuming to create and difficult to keep current.
More importantly, the relationship between discovery results, permission information, scan context and supporting evidence was easy to lose.
The start of the project
After retiring in the spring of 2026, I decided to explore whether the main stages of file-share discovery, inventory, permission collection and analysis could be brought together in one application.
That became the Share Monitoring project, shortened to ShareMon.
The objective is not simply to create another share scanner. ShareMon is intended to preserve the context needed for review: where a share was found, which credentials were used, what permissions were obtained, which scan produced the result and what further analysis was performed.
Development approach
ShareMon is currently tested in a private lab containing a domain controller, Windows servers and workstations in a test Active Directory environment.
New functionality is added as specific discovery, permission and analysis requirements are identified and tested.
The lab is used to reproduce broad permissions, nested groups, direct user access, unresolved SIDs and different credential contexts.
ShareMon records observations and supporting information. Whether access is appropriate still depends on the approved audience and purpose of the individual share.
The project remains under active development. Workflows, interface details, database fields and documentation may change as testing continues.
Project principles
Explore ShareMon
Read the product overview, review the documentation or contact the project about a private evaluation.