PowerShell Deleted Mounted Share

 Original Source: [Sigma source]
Title: PowerShell Deleted Mounted Share
Status: test
Description:Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md
Author: oscd.community, @redcanary, Zach Stanford @svch0st
Date: 2020-10-08
modified:2025-10-07
Tags:
  • -'attack.stealth'
  • -'attack.t1070.005'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains:
      -'Remove-SmbShare'
      -'Remove-FileShare'

  filter_main_module_load:
    ScriptBlockText|contains|all:
      -'FileShare.cdxml'
      -'Microsoft.PowerShell.Core\Export-ModuleMember'
      -'ROOT/Microsoft/Windows/Storage/MSFT_FileShare'
      -'ObjectModelWrapper'
      -'Cmdletization.MethodParameter'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Administrators or Power users may remove their shares via cmd line
Level: medium