Product overview

One central view of share discovery, permissions and analysis

ShareMon combines target-based discovery, remote Windows share enumeration, authoritative Agent scans, permission collection and advanced analysis in a central SQLite-backed inventory.

Purpose

Build a clearer view of Windows file shares

File-share information may be distributed across Active Directory, DFS namespaces, individual Windows servers, imported records and earlier scan results. ShareMon brings this information into a central inventory for administrative review.

Discover shares

Identify scan targets through IP and Active Directory-based discovery, enumerate DFS namespace references, and remotely enumerate Windows shares.

Maintain an inventory

Record UNC paths, servers, share names, share types, comments, scan identifiers and related metadata.

Review permissions

Collect SMB Level 0 access information and NTFS Level 1+ permission information where the scan context permits it.

Analyse selected shares

Produce directory, ACL, extension, filename-keyword and plaintext content-keyword results.

Scan context

Results reflect the access of the credentials used

ShareMon can perform supported discovery and analysis operations using the current Windows credentials or alternative credentials. The information returned by a scan depends on what those credentials are permitted to discover, enumerate and read.

A regular user running ShareMon will therefore normally see only the shares, directories and permission information available within that user's access context.

Why limited-access scans are valuable

A scan performed with a standard or generic user account provides a practical view of what another user with equivalent access can reach.

Shares or content visible in that context may warrant review, particularly where the access is broader than intended, inherited through general domain membership, or inconsistent with the share's business purpose.

Standard-user scan

Shows the practical access available to the selected user context. This is useful for identifying shares and content that are exposed to users with the same effective access.

Administrative scan

A scan performed with appropriate server-level administrative access can return a broader and more complete view of the server's shares and permissions.

Agent scan

The ShareMon Agent runs locally on the file server, normally as LocalSystem, and provides authoritative local share and permission information for import into the central database.

Architecture

Two cooperating components

ShareMon uses a central management application together with an optional local Agent for authoritative scans on Windows file servers.

ShareMon central application

ShareMon.exe provides central discovery, inventory, reporting and advanced analysis.

  • IP, Active Directory and DFS discovery
  • Central SQLite database
  • Latest-scan and all-known-shares views
  • Advanced analysis and result generation
  • Import of authoritative Agent scans

ShareMon Agent

The Agent runs locally on a file server, normally as LocalSystem, and writes scan information to a separate SQLite database using the same schema.

  • Authoritative local share enumeration
  • SMB access collection using Get-SmbShareAccess
  • NTFS permission collection
  • Agent version and last-seen information
  • Share counts and scan-run records
Read about the Agent

Discovery

Multiple approaches to share discovery

ShareMon can identify scan targets through IP-based and Active Directory-based discovery, and can enumerate DFS namespaces to identify referenced share locations.

IP-based discovery

Use configured IP addresses or ranges as the basis for locating systems and remotely enumerating their Windows shares.

Active Directory-based discovery

Use computer information from Active Directory to identify systems that can then be scanned for Windows shares.

DFS-based discovery

Enumerate DFS namespace information to identify referenced share locations and their underlying targets.

Imported and stored share selections

Work from imported share lists, shares from the latest scan, or all known shares already recorded in the central database.

Inventory

Recorded share and scan information

ShareMon records information needed to identify the share, understand how it was scanned and relate it to a specific scan run.

Share identityUNC path, server, share name and share type
Descriptive informationShare comments and related metadata
Scan contextCredentials used, ACL status and ScanRunId
Agent informationAgent version, status, last seen and share count

Advanced analysis

Analyse selected directories and permissions

Advanced Analysis can generate directory, permission and keyword-based results for selected shares. Operations can be paused, resumed or cancelled, with progress available through the live log.

Explore Advanced Analysis
  • Raw directory listing
  • Tree directory output
  • Directory ACL Shift and ACL listing
  • SMB Level 0 ACL
  • NTFS Level 1+ ACL
  • File extension analysis
  • Filename keyword analysis
  • Plaintext content keyword analysis

Data and output

Databases, logs and result files

ShareMon stores structured scan information in SQLite databases. It also creates log files, debugging information and result files in text or CSV formats, depending on the operation.

Credential handling

ShareMon can use the current Windows credentials or alternative credentials during supported operations.

ShareMon does not store credential passwords.

Next steps

Learn more about ShareMon

Read the technical documentation or request access to discuss a private evaluation.