Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0103 — Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
DET0103

Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0286 Analytic 0286
Windows

Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=1 WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 NSM:Flow SMB2_LOGOFF/SMB_TREE_DISCONNECT
[TimeWindow] Adjustable window to correlate CLI disconnection command with SMB session teardown (e.g., 5 mins)
[UserContext] Used to filter on non-interactive users or highly privileged accounts
[ProcessCommandLineRegex] Patterns to match `net use \\host\share /delete`, `Remove-SmbMapping`, or suspicious batched disconnections
[NetworkShareNamePattern] Tunable list of shares likely targeted (e.g., ADMIN$, C$, IPC$)

Detected Techniques

1

Details

MITRE ID
DET0103
STIX ID
x-mitre-detection-strategy--00060b87-7f99-45aa-9553-a4d94139195c
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.