{"id":"T1070.005","name":"Network Share Connection Removal","url":"https://attack.mitre.org/techniques/T1070/005","tactics":["stealth"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0103","stix_id":"x-mitre-detection-strategy--00060b87-7f99-45aa-9553-a4d94139195c","name":"Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects","url":"https://attack.mitre.org/detectionstrategies/DET0103","analytics":[{"id":"AN0286","stix_id":"x-mitre-analytic--5d47e6b2-04fb-45ab-be98-7de1baabf508","name":"Analytic 0286","description":"Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity.","url":"https://attack.mitre.org/detectionstrategies/DET0103#AN0286","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"NSM:Flow","channel":"SMB2_LOGOFF/SMB_TREE_DISCONNECT","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Adjustable window to correlate CLI disconnection command with SMB session teardown (e.g., 5 mins)"},{"field":"UserContext","description":"Used to filter on non-interactive users or highly privileged accounts"},{"field":"ProcessCommandLineRegex","description":"Patterns to match `net use \\\\host\\share /delete`, `Remove-SmbMapping`, or suspicious batched disconnections"},{"field":"NetworkShareNamePattern","description":"Tunable list of shares likely targeted (e.g., ADMIN$, C$, IPC$)"}],"live":true,"detection_strategies":["DET0103"],"techniques":["T1070.005"]}],"live":true,"version":"1.0","techniques":["T1070.005"]}],"sigma_rules":[{"id":"0e6a9e62-627e-496c-aef5-bfa39da29b5e","title":"MaxMpxCt Registry Value Changed","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2024-03-19","modified":null,"description":"Detects changes to the \"MaxMpxCt\" registry value.\nMaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate.\nRansomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.\n","references":["https://www.huntress.com/blog/blackcat-ransomware-affiliate-ttps","https://securityscorecard.com/research/deep-dive-into-alphv-blackcat-ransomware","https://www.intrinsec.com/alphv-ransomware-gang-analysis/?cn-reloaded=1","https://www.sentinelone.com/labs/blackcat-ransomware-highly-configurable-rust-driven-raas-on-the-prowl-for-victims/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.stealth","attack.t1070.005"],"path":"rules/windows/registry/registry_set/registry_set_optimize_file_sharing_network.yml","techniques":["T1070.005"],"cves":[]},{"id":"66a4d409-451b-4151-94f4-a55d559c49b0","title":"PowerShell Deleted Mounted Share","author":"oscd.community, @redcanary, Zach Stanford @svch0st","status":"test","level":"medium","date":"2020-10-08","modified":"2025-10-07","description":"Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.t1070.005"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_mounted_share_deletion.yml","techniques":["T1070.005"],"cves":[]},{"id":"c7dcacd0-cc59-4004-b0a4-1d6cdebe6f3e","title":"Disable Administrative Share Creation at Startup","author":"frack113","status":"test","level":"medium","date":"2022-01-16","modified":"2024-03-25","description":"Administrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md#atomic-test-4---disable-administrative-share-creation-at-startup"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.stealth","attack.t1070.005"],"path":"rules/windows/registry/registry_set/registry_set_disable_administrative_share.yml","techniques":["T1070.005"],"cves":[]},{"id":"cb7c4a03-2871-43c0-9bbb-18bbdb079896","title":"Unmount Share Via Net.EXE","author":"oscd.community, @redcanary, Zach Stanford @svch0st","status":"test","level":"low","date":"2020-10-08","modified":"2023-02-21","description":"Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1070.005"],"path":"rules/windows/process_creation/proc_creation_win_net_share_unmount.yml","techniques":["T1070.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}