PowerShell Removal of Mounted SMB/Fileshares via Remove-SmbShare or Remove-FileShare

Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.

FreeUnreviewedSigmamediumv1
title: PowerShell Removal of Mounted SMB/Fileshares via Remove-SmbShare or Remove-FileShare
id: a41a4d18-b82f-4cec-864e-2801efcee4ee
status: test
description: This rule identifies PowerShell script-block activity that calls Remove-SmbShare or Remove-FileShare, indicating a mounted share connection was removed. Adversaries may tear down share mappings to reduce evidence left in the environment and limit access after performing actions. It relies on PowerShell Script Block Logging telemetry containing the relevant cmdlet names in script blocks.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1070.005/T1070.005.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_susp_mounted_share_deletion.yml
author: oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule Team
date: 2020-10-08
modified: 2025-10-07
tags:
  - attack.stealth
  - attack.t1070.005
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection:
    ScriptBlockText|contains:
      - Remove-SmbShare
      - Remove-FileShare
  filter_main_module_load:
    ScriptBlockText|contains|all:
      - FileShare.cdxml
      - Microsoft.PowerShell.Core\Export-ModuleMember
      - ROOT/Microsoft/Windows/Storage/MSFT_FileShare
      - ObjectModelWrapper
      - Cmdletization.MethodParameter
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Administrators or Power users may remove their shares via cmd line
level: medium
license: DRL-1.1
related:
  - id: 66a4d409-451b-4151-94f4-a55d559c49b0
    type: derived

What it detects

This rule identifies PowerShell script-block activity that calls Remove-SmbShare or Remove-FileShare, indicating a mounted share connection was removed. Adversaries may tear down share mappings to reduce evidence left in the environment and limit access after performing actions. It relies on PowerShell Script Block Logging telemetry containing the relevant cmdlet names in script blocks.

Known false positives

  • Administrators or Power users may remove their shares via cmd line

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.