1200KM / simulation
T1070.005 Network Share Connection Removal — Attack Simulation
Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\system\share /delete command.
Technique description
Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the net use \\system\share /delete command.
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Remove Network Share PowerShell
Procedure 0512d214-9512-4d22-bde7-f37e058259b3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Remove Network Share
Procedure 09210ad5-1ef2-4077-9ad3-7351e13e9222; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Add Network Share
Procedure 14c38f32-6509-46d8-ab43-d53e32d2b131; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Remove Administrative Shares
Procedure 4299eff5-90f1-4446-b2f3-7f4f5cfd5d62; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Disable Administrative Share Creation at Startup
Procedure 99c657aa-ebeb-4179-a665-69288fdd12b8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.