Executive Summary
In June 2026, Praetorian released Sulla, an open-source tool designed to scan SMB shares for exposed credentials across enterprise networks. Sulla automates the discovery of readable SMB shares, traverses their file structures, and scans contents for sensitive information using the Titus detection library. This tool addresses the challenge of manually reviewing numerous network shares, which is often tedious and inefficient. By integrating Sulla into their Continuous Threat Exposure Management platform, Guard, Praetorian ensures that SMB secrets are identified promptly as they appear in environments.
The release of Sulla highlights the growing need for automated tools to detect and mitigate the risks associated with exposed credentials in network shares. As organizations increasingly rely on complex network infrastructures, tools like Sulla become essential in proactively identifying and addressing security vulnerabilities, thereby enhancing overall cybersecurity posture.
Why This Matters Now
The release of Sulla underscores the critical importance of proactively identifying and mitigating exposed credentials within enterprise networks. As cyber threats continue to evolve, leveraging automated tools like Sulla is essential for maintaining robust security defenses and preventing potential breaches.
Attack Path Analysis
An attacker exploited exposed SMB shares to gain initial access, escalated privileges by obtaining administrative credentials, moved laterally by accessing additional network shares, established command and control through SMB sessions, exfiltrated sensitive data from compromised shares, and impacted the organization by deploying ransomware via SMB shares.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited exposed SMB shares to gain unauthorized access to the network.
MITRE ATT&CK® Techniques
File and Directory Discovery
Unsecured Credentials: Credentials in Files
Data from Local System
Application Layer Protocol: SMB/Windows Admin Shares
Remote Services: SMB/Windows Admin Shares
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Limit access to system components and cardholder data to only those individuals whose job requires such access.
Control ID: 7.1.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong identity and access management controls.
Control ID: Pillar 2: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
SMB secret scanning tool release exposes critical credentials vulnerability in network shares containing banking APIs, encryption keys, and compliance-regulated data requiring immediate remediation.
Health Care / Life Sciences
Sulla's SMB credential discovery capabilities highlight HIPAA compliance risks from exposed patient data access credentials and encryption keys stored in healthcare network shares.
Information Technology/IT
Open source SMB secret scanner directly impacts IT infrastructure security by exposing cloud credentials, SSH keys, and database connections across enterprise network environments.
Government Administration
Security tool release demonstrates significant risk to government networks where classified credentials and infrastructure secrets may be exposed through vulnerable SMB shares.
Sources
- Sharing is Caring: SMB Secret Scanning with Sullahttps://www.praetorian.com/blog/sharing-is-caring-smb-secret-scanning-with-sulla/Verified
- SMB Protocol Exploitation - PenTesting.Orghttps://www.pentesting.org/file-sharing-attacks/Verified
- SMB Vulnerabilities Scanner | Security Testing | TigerStrikehttps://www.tigerstrike.io/scanners/smb-vulnerabilities/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit exposed SMB shares, thereby reducing the potential blast radius within the network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing CNSF would likely restrict unauthorized access to SMB shares, thereby limiting the attacker's initial entry points.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting access to sensitive resources based on strict identity verification.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit lateral movement by controlling and monitoring internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the establishment of command and control channels by monitoring and controlling cross-cloud communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
Implementing CNSF controls would likely limit the spread of ransomware by restricting unauthorized access and movement within the network.
Impact at a Glance
Affected Business Functions
- File Sharing Services
- Network Security Monitoring
- Credential Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive credentials stored in SMB shares, including cloud provider keys, database connection strings, and private keys.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access to SMB shares based on identity and context.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic from SMB shares.
- • Deploy Inline IPS (Suricata) to detect and prevent malicious activities over SMB protocols.
- • Utilize Threat Detection & Anomaly Response to identify and respond to unusual SMB access patterns.
- • Ensure Encrypted Traffic (HPE) to protect data in transit over SMB connections.



