Skip to the content.

back

Find sigma rule :heavy_check_mark:

Attack: Indicator Removal on Host: Network Share Connection Removal

Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\system\share /delete command. (Citation: Technet Net Use)

MITRE

Tactic

technique

Test : Remove Network Share

OS

Description:

Removes a Network Share utilizing the command_prompt

Executor

command_prompt

Sigma Rule

back