PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
- Product
- windows
- Category
- ps_script
- Author
- oscd.community, @redcanary, Zach Stanford @svch0st (SigmaHQ), DRL 1.1
- Published
- 2020-10-08
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell activity where scripts attempt to remove mounted network shares using Remove-SmbShare or Remove-FileShare. Attackers can use share removal to clean up connections and reduce evidence of access. It relies on Script Block Logging telemetry to match specific cmdlets within PowerShell script blocks and on additional script-block module-loading context to reduce noise.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
id: a41a4d18-b82f-4cec-864e-2801efcee4ee
status: test
description: This rule flags PowerShell activity where scripts attempt to remove mounted network shares using Remove-SmbShare or Remove-FileShare. Attackers can use share removal to clean up connections and reduce evidence of access. It relies on Script Block Logging telemetry to match specific cmdlets within PowerShell script blocks and on additional script-block module-loading context to reduce noise.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_mounted_share_deletion.yml
author: oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule Team
date: 2020-10-08
modified: 2025-10-07
tags:
- attack.stealth
- attack.t1070.005
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains:
- Remove-SmbShare
- Remove-FileShare
filter_main_module_load:
ScriptBlockText|contains|all:
- FileShare.cdxml
- Microsoft.PowerShell.Core\Export-ModuleMember
- ROOT/Microsoft/Windows/Storage/MSFT_FileShare
- ObjectModelWrapper
- Cmdletization.MethodParameter
condition: selection and not 1 of filter_main_*
falsepositives:
- Administrators or Power users may remove their shares via cmd line
level: medium
license: DRL-1.1
related:
- id: 66a4d409-451b-4151-94f4-a55d559c49b0
type: derived