Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 1.13 KB

MATCH-S00441.md

File metadata and controls

34 lines (27 loc) · 1.13 KB

Rules: Delete Windows Share

Description

Observes for net.exe being used to delete a network share.

Additional Details

Detail Value
Type Templated Match
Category Lateral Movement
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Delete Windows Share
Summary Expression A user: {{user_username}} has executed a command to delete a network share on host: {{device_hostname}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0008, _mitreAttackTactic:TA0005, _mitreAttackTechnique:T1021, _mitreAttackTechnique:T1070, _mitreAttackTechnique:T1070.005, _mitreAttackTechnique:T1021.002

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username