Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1070.005 — Network Share Connection Removal
T1070.005

Network Share Connection Removal

Stealth
TLP:CLEAR

Description

Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the <code>net use \\system\share /delete</code> command. (Citation: Technet Net Use)

MITRE ATT&CK Detection Strategies
1

DET0103 Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
AN0286 Windows

Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell NSM:Flow

Details

Platforms
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.