title: Unmount Share Via Net.EXE id: cb7c4a03-2871-43c0-9bbb-18bbdb079896 status: test description: Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation references: - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md author: oscd.community, @redcanary, Zach Stanford @svch0st date: 2020-10-08 modified: 2023-02-21 tags: - attack.stealth - attack.t1070.005 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: - '\net.exe' - '\net1.exe' - OriginalFileName: - 'net.exe' - 'net1.exe' selection_cli: CommandLine|contains|all: - 'share' - '/delete' condition: all of selection* falsepositives: - Administrators or Power users may remove their shares via cmd line level: low