The Containment Era is here. →Explore

Executive Summary

In June 2026, Praetorian released Sulla, an open-source tool designed to scan SMB shares for exposed credentials across enterprise networks. Sulla automates the discovery of readable SMB shares, traverses their file structures, and scans contents for sensitive information using the Titus detection library. This tool addresses the challenge of manually reviewing numerous network shares, which is often tedious and inefficient. By integrating Sulla into their Continuous Threat Exposure Management platform, Guard, Praetorian ensures that SMB secrets are identified promptly as they appear in environments.

The release of Sulla highlights the growing need for automated tools to detect and mitigate the risks associated with exposed credentials in network shares. As organizations increasingly rely on complex network infrastructures, tools like Sulla become essential in proactively identifying and addressing security vulnerabilities, thereby enhancing overall cybersecurity posture.

Why This Matters Now

The release of Sulla underscores the critical importance of proactively identifying and mitigating exposed credentials within enterprise networks. As cyber threats continue to evolve, leveraging automated tools like Sulla is essential for maintaining robust security defenses and preventing potential breaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Sulla is an open-source SMB secret scanner developed by Praetorian to discover credentials exposed in SMB shares across enterprise networks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit exposed SMB shares, thereby reducing the potential blast radius within the network.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Implementing CNSF would likely restrict unauthorized access to SMB shares, thereby limiting the attacker's initial entry points.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by restricting access to sensitive resources based on strict identity verification.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security would likely limit lateral movement by controlling and monitoring internal traffic between workloads.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control would likely limit the establishment of command and control channels by monitoring and controlling cross-cloud communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.

Impact (Mitigations)

Implementing CNSF controls would likely limit the spread of ransomware by restricting unauthorized access and movement within the network.

Impact at a Glance

Affected Business Functions

  • File Sharing Services
  • Network Security Monitoring
  • Credential Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive credentials stored in SMB shares, including cloud provider keys, database connection strings, and private keys.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access to SMB shares based on identity and context.
  • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic from SMB shares.
  • Deploy Inline IPS (Suricata) to detect and prevent malicious activities over SMB protocols.
  • Utilize Threat Detection & Anomaly Response to identify and respond to unusual SMB access patterns.
  • Ensure Encrypted Traffic (HPE) to protect data in transit over SMB connections.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image