PowerShell Removal of Mounted SMB/Fileshares via Remove-SmbShare or Remove-FileShare
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
FreeUnreviewedSigmamediumv1
powershell-removal-of-mounted-smb-fileshares-via-remove-smbshare-or-remove-files-66a4d409
title: PowerShell Removal of Mounted SMB/Fileshares via Remove-SmbShare or Remove-FileShare
id: a41a4d18-b82f-4cec-864e-2801efcee4ee
status: test
description: This rule identifies PowerShell script-block activity that calls Remove-SmbShare or Remove-FileShare, indicating a mounted share connection was removed. Adversaries may tear down share mappings to reduce evidence left in the environment and limit access after performing actions. It relies on PowerShell Script Block Logging telemetry containing the relevant cmdlet names in script blocks.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_mounted_share_deletion.yml
author: oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule Team
date: 2020-10-08
modified: 2025-10-07
tags:
- attack.stealth
- attack.t1070.005
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains:
- Remove-SmbShare
- Remove-FileShare
filter_main_module_load:
ScriptBlockText|contains|all:
- FileShare.cdxml
- Microsoft.PowerShell.Core\Export-ModuleMember
- ROOT/Microsoft/Windows/Storage/MSFT_FileShare
- ObjectModelWrapper
- Cmdletization.MethodParameter
condition: selection and not 1 of filter_main_*
falsepositives:
- Administrators or Power users may remove their shares via cmd line
level: medium
license: DRL-1.1
related:
- id: 66a4d409-451b-4151-94f4-a55d559c49b0
type: derived
What it detects
This rule identifies PowerShell script-block activity that calls Remove-SmbShare or Remove-FileShare, indicating a mounted share connection was removed. Adversaries may tear down share mappings to reduce evidence left in the environment and limit access after performing actions. It relies on PowerShell Script Block Logging telemetry containing the relevant cmdlet names in script blocks.
Known false positives
- Administrators or Power users may remove their shares via cmd line
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.