Skip to content

Hide Navigation Hide TOC

Unmount Share Via Net.EXE (cb7c4a03-2871-43c0-9bbb-18bbdb079896)

Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation

Cluster A Galaxy A Cluster B Galaxy B Level
Network Share Connection Removal - T1070.005 (a750a9f6-0bde-4bb3-9aae-1e2786e9780c) Attack Pattern Unmount Share Via Net.EXE (cb7c4a03-2871-43c0-9bbb-18bbdb079896) Sigma-Rules 1
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) Attack Pattern Network Share Connection Removal - T1070.005 (a750a9f6-0bde-4bb3-9aae-1e2786e9780c) Attack Pattern 2