Techniques › T1070 › T1070.005
T1070.005 Network Share Connection Removal
stealth — Windows · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
4
Sigma rules tagged attack.t1070.005
0
KEV CVEs mapped here
<p>Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the <code>net use \\system\share /delete</code> command.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0103 Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects v1.0
AN0286 WindowsDetects network share disconnection attempts using command-line tools like
net use /delete, PowerShellRemove-SmbMapping, and correlation with process lineage and SMB session teardown activity.Tunable:TimeWindowUserContextProcessCommandLineRegexNetworkShareNamePattern
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1070.005
Author: Nasreddine Bencherchali (Nextron Systems)
· 2024-03-19 · logsource: product=windows category=registry_set · 0e6a9e62-627e-496c-aef5-bfa39da29b5e
Detects changes to the "MaxMpxCt" registry value.
MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate.
Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.
Author: oscd.community, @redcanary, Zach Stanford @svch0st
· 2020-10-08 (modified 2025-10-07) · logsource: product=windows category=ps_script · 66a4d409-451b-4151-94f4-a55d559c49b0
Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
Author: frack113
· 2022-01-16 (modified 2024-03-25) · logsource: product=windows category=registry_set · c7dcacd0-cc59-4004-b0a4-1d6cdebe6f3e
Administrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system
Author: oscd.community, @redcanary, Zach Stanford @svch0st
· 2020-10-08 (modified 2023-02-21) · logsource: product=windows category=process_creation · cb7c4a03-2871-43c0-9bbb-18bbdb079896
Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
Rules tagged at the parent level (attack.t1070) 20
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-09-02 · logsource: product=windows category=process_creation · 0649be4a-aeb0-45b0-b89e-7f1668f6d9c0
Detects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks.
Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.
Author: Christian Burkard (Nextron Systems)
· 2021-10-19 (modified 2023-02-08) · logsource: product=windows category=registry_delete · 07bdd2f5-9c58-4f38-aec8-e101bb79ef8d
Detects the deletion of registry keys containing the MSTSC connection history
Author: Christian Burkard (Nextron Systems)
· 2021-08-27 (modified 2023-01-23) · logsource: product=windows service=msexchange-management · 09570ae5-889e-43ea-aac0-0e1221fb3d95
Detects removal of an exported Exchange mailbox which could be to cover tracks from ProxyShell exploit
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-06-28 (modified 2022-11-25) · logsource: product=windows category=ps_script · 115fdba9-f017-42e6-84cf-d5573bf2ddf8
Detects usage of powershell cmdlets to disable or remove ETW trace sessions
Author: Janantha Marasinghe
· 2022-12-13 (modified 2022-12-28) · logsource: product=aws service=cloudtrail · 20f754db-d025-4a8f-9d74-e0037e999a9a
Detects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-02-16 · logsource: product=windows category=file_delete · 270185ff-5f50-4d6d-a27f-24c3b8c9fef8
Detects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence
Author: Leo Tsaousis (@laripping)
· 2024-03-26 · logsource: product=kubernetes category=application service=audit · 3132570d-cab2-4561-9ea6-1743644b2290
Detects when events are deleted in Kubernetes.
An adversary may delete Kubernetes events in an attempt to evade detection.
Author: Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2022-09-16 (modified 2023-02-15) · logsource: product=windows category=file_delete · 3eb8c339-a765-48cc-a150-4364c04652bf
Detects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-02-13 (modified 2025-10-07) · logsource: product=windows category=process_creation · 4931188c-178e-4ee7-a348-39e8a7a56821
Detect filter driver unloading activity via fltmc.exe
Author: Kirill Kiryanov, oscd.community
· 2019-10-23 (modified 2023-02-13) · logsource: product=windows category=process_creation · 4d7cda18-1b12-4e52-b45c-d28653210df8
Detects possible Sysmon filter driver unloaded via fltmc.exe
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-02-15 · logsource: product=windows category=file_delete · 63c779ba-f638-40a0-a593-ddd45e8b1ddc
Detects the deletion of the event log files which may indicate an attempt to destroy forensic evidence
Author: Tuan Le (NCSGroup), Nasreddine Bencherchali (Nextron Systems)
· 2023-03-09 · logsource: product=linux category=process_creation · 95d61234-7f56-465c-6f2d-b562c6fedbc4
Detects linux package removal using builtin tools such as "yum", "apt", "apt-get" or "dpkg".
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-17 (modified 2023-09-18) · logsource: product=windows category=image_load · 9e9a9002-56c4-40fd-9eff-e4b09bfa5f6c
Detects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
Author: @neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
· 2019-03-22 (modified 2022-06-28) · logsource: product=windows category=process_creation · a238b5d0-ce2d-4414-a676-7a531b3d13d6
Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-26 (modified 2022-12-30) · logsource: product=windows category=file_delete · a55349d8-9588-4c5a-8e3b-1925fe2a4ffe
Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence
Author: Ecco, E.M. Anhaus, oscd.community
· 2019-09-26 (modified 2023-09-09) · logsource: product=windows category=process_creation · add64136-62e5-48ea-807e-88638d02df1e
Detects suspicious parameters of fsutil (deleting USN journal, configuring it with small size, etc).
Might be used by ransomwares during the attack (seen by NotPetya and others).
Author: Austin Songer @austinsonger
· 2021-11-25 (modified 2022-12-25) · logsource: product=windows category=ps_script · bde47d4b-9987-405c-94c7-b080410e8ea7
Identifies when a user attempts to clear console history. An adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
Author: Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)
· 2019-10-22 (modified 2022-11-03) · logsource: product=windows category=process_creation · c947b146-0abc-4c87-9c64-b17e9d7274a2
Shadow Copies deletion using operating systems utilities
Author: @neu5ron
· 2019-02-07 (modified 2023-02-15) · logsource: product=windows category=process_creation · c9fbe8e9-119d-40a6-9b59-dd58a5d84429
Detects potential malicious and unauthorized usage of bcdedit.exe
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-02-15 · logsource: product=windows category=file_delete · ff301988-c231-4bd0-834c-ac9d73b86586
Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence