> For the complete documentation index, see [llms.txt](https://viperone.gitbook.io/pentest-everything/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://viperone.gitbook.io/pentest-everything/everything/everything-active-directory/defense-evasion/indicator-removal/network-share-connection-removal.md).

# Network Share Connection Removal

https\://attack.mitre.org/techniques/T1070/005/

**ATT\&CK ID:** [T1070.005](https://attack.mitre.org/techniques/T1070/005/)

**Permissions Required:** <mark style="color:red;">**Administrator**</mark> | <mark style="color:green;">**User**</mark>

**Description**

Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin Shares connections can be removed when no longer needed. Net is an example utility that can be used to remove network share connections with the `net use \system\share /delete` command.

\[[Source](https://attack.mitre.org/techniques/T1070/005/)]

## Techniques

### Net (Native)

```
net use i: /delete
net use l: /delete
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FHR7QO4pormUwVjrObC7K%2Fnet-use-delete.png?alt=media\&token=e974392e-899e-415b-aef7-fe0e0cf45f9b)

### Registry

```bash
# Query for mapped drives
reg query HKEY_CURRENT_USER\Network

reg delete HKEY_CURRENT_USER\Network\i /f

# Query secondary mapped drive keys
reg query HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

# Delete secondary mapped drive keys
reg delete HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\##DC01#IT /f
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2FdkcrJftTfYDQnB7DcZj1%2Fregistry-delete-mapped-drives.png?alt=media\&token=d0f58322-36e6-4cc6-9a0b-6e1e14b3439b)

## Mitigation

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.

## Further Reading

**NET USE:** <https://ss64.com/nt/net-use.html>
