intermediate

SMB and the workstation/server services

How Windows shares and consumes files over the network — the client redirector and server driver behind every UNC path.

Related labs

Hands-on exercises for this area — in the browser or on a Windows machine.

View all labs

Guided paths in this branch

Follow a short sequence step by step. Each path links to the first topic; use Read next on each page to continue.

Why it matters

Every \\server\share path, every mapped drive, and most lateral movement in a Windows network runs over SMB. It is also the classic 'integral subsystem' pair (Workstation service, Server service) from the Windows architecture diagram, and one of the least understood parts of the stack.

Mental model

A remote file share looks like an ordinary path to applications because a redirector driver makes a network protocol look like a local file system underneath the same VFS-style I/O path every other file uses.

How it works

  1. 1The Workstation service (LanmanWorkstation) and its kernel-mode redirector (the MUP and mrxsmb-family drivers) make a remote \\server\share path resolve through the ordinary I/O Manager path, as if it were a local volume.
  2. 2The Server service (LanmanServer) and its kernel-mode driver (srv2.sys) expose local file systems as network shares, authenticating and authorizing each request the same way a local access check would.
  3. 3The SMB protocol itself (SMB2/SMB3 today) carries the actual read/write/metadata operations, with SMB3 adding encryption and multichannel for both security and throughput.

Key terms

Redirector
The kernel-mode driver that makes a remote SMB share appear as an ordinary file-system path to applications.
MUP
Multiple UNC Provider; routes a \\server\share path to whichever redirector claims it.
LanmanWorkstation / LanmanServer
The user-mode services that configure and coordinate the SMB client and server respectively.

Why a mapped network drive behaves like a local one

Opening a file on a mapped drive uses the exact same CreateFile/NtCreateFile path as a local file. The redirector intercepts the request early enough that everything above it — the loader, an application's own file I/O calls — never has to know the data is coming from another machine.

Common misconception

People treat SMB as 'just a file-sharing protocol' separate from core Windows internals. In practice it's wired directly into the same I/O Manager and VFS-style path every other file access uses, which is exactly why it behaves — and fails — the way local storage does.

You should read next

Ranked from your current topic, related links, branch depth, and any active guided path.

Related topics