Sub-technique of T1070 Indicator Removal.View on attack.mitre.org
Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\system\share /delete command.
Rules on DetectionCode tagged with T1070.005.
| Rule | Level | Log source |
|---|---|---|
| Disable Administrative Share Creation at Startup | medium | windows / registry_set |
| PowerShell Deleted Mounted Share | medium | windows / ps_script |
| MaxMpxCt Registry Value Changed | low | windows / registry_set |
| Unmount Share Via Net.EXE | low | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Create or delete windows shares using net exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupThreat Group-3390 | Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection. |
| Used by | Procedure example |
|---|---|
| MalwareDUSTTRAP | DUSTTRAP can remove network shares from infected systems. |
| MalwareInvisiMole | InvisiMole can disconnect previously connected remote drives. |
| ToolNet | The |
| MalwareRobbinHood | RobbinHood disconnects all network shares from the computer with the command |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.