Discover shares
Identify scan targets through IP and Active Directory-based discovery, enumerate DFS namespace references, and remotely enumerate Windows shares.
Product overview
ShareMon combines target-based discovery, remote Windows share enumeration, authoritative Agent scans, permission collection and advanced analysis in a central SQLite-backed inventory.
Purpose
File-share information may be distributed across Active Directory, DFS namespaces, individual Windows servers, imported records and earlier scan results. ShareMon brings this information into a central inventory for administrative review.
Identify scan targets through IP and Active Directory-based discovery, enumerate DFS namespace references, and remotely enumerate Windows shares.
Record UNC paths, servers, share names, share types, comments, scan identifiers and related metadata.
Collect SMB Level 0 access information and NTFS Level 1+ permission information where the scan context permits it.
Produce directory, ACL, extension, filename-keyword and plaintext content-keyword results.
Scan context
ShareMon can perform supported discovery and analysis operations using the current Windows credentials or alternative credentials. The information returned by a scan depends on what those credentials are permitted to discover, enumerate and read.
A regular user running ShareMon will therefore normally see only the shares, directories and permission information available within that user's access context.
A scan performed with a standard or generic user account provides a practical view of what another user with equivalent access can reach.
Shares or content visible in that context may warrant review, particularly where the access is broader than intended, inherited through general domain membership, or inconsistent with the share's business purpose.
Architecture
ShareMon uses a central management application together with an optional local Agent for authoritative scans on Windows file servers.
ShareMon.exe provides central discovery, inventory, reporting and advanced analysis.
The Agent runs locally on a file server, normally as LocalSystem, and writes scan information to a separate SQLite database using the same schema.
Discovery
ShareMon can identify scan targets through IP-based and Active Directory-based discovery, and can enumerate DFS namespaces to identify referenced share locations.
Use configured IP addresses or ranges as the basis for locating systems and remotely enumerating their Windows shares.
Use computer information from Active Directory to identify systems that can then be scanned for Windows shares.
Enumerate DFS namespace information to identify referenced share locations and their underlying targets.
Work from imported share lists, shares from the latest scan, or all known shares already recorded in the central database.
Inventory
ShareMon records information needed to identify the share, understand how it was scanned and relate it to a specific scan run.
Advanced analysis
Advanced Analysis can generate directory, permission and keyword-based results for selected shares. Operations can be paused, resumed or cancelled, with progress available through the live log.
Explore Advanced AnalysisData and output
ShareMon stores structured scan information in SQLite databases. It also creates log files, debugging information and result files in text or CSV formats, depending on the operation.
ShareMon can use the current Windows credentials or alternative credentials during supported operations.
ShareMon does not store credential passwords.
Next steps
Read the technical documentation or request access to discuss a private evaluation.