Unmount Share Via Net.EXE

 Original Source: [Sigma source]
Title: Unmount Share Via Net.EXE
Status: test
Description:Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md
Author: oscd.community, @redcanary, Zach Stanford @svch0st
Date: 2020-10-08
modified:2023-02-21
Tags:
  • -'attack.stealth'
  • -'attack.t1070.005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\net.exe'
      - '\net1.exe'
    - OriginalFileName:
      - 'net.exe'
      - 'net1.exe'
  selection_cli:
    CommandLine|contains|all:
      -'share'
      -'/delete'

  condition:all of selection*
Falsepositives:
  -Administrators or Power users may remove their shares via cmd line
Level: low