Network Share Connection Removal

T1070.005

Sub-technique of T1070 Indicator Removal.View on attack.mitre.org

About this technique

Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\system\share /delete command.

Detection rules5

Rules on DetectionCode tagged with T1070.005.

Sigma4

RuleLevelLog source
Disable Administrative Share Creation at Startupmediumwindows / registry_set
PowerShell Deleted Mounted Sharemediumwindows / ps_script
MaxMpxCt Registry Value Changedlowwindows / registry_set
Unmount Share Via Net.EXElowwindows / process_creation

Splunk1

RuleTypeRiskData source
Create or delete windows shares using net exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software4

Campaigns0

None recorded.

Procedure examples5

Groups1

Used byProcedure example
GroupThreat Group-3390

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.

Software4

Used byProcedure example
MalwareDUSTTRAP

DUSTTRAP can remove network shares from infected systems.

MalwareInvisiMole

InvisiMole can disconnect previously connected remote drives.

ToolNet

The net use \\system\share /delete command can be used in Net to remove an established connection to a network share.

MalwareRobbinHood

RobbinHood disconnects all network shares from the computer with the command net use * /DELETE /Y.

References1

  1. Technet Net Use Open source
    Microsoft. (n.d.). Net Use. Retrieved November 25, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.