Skip to content
Security

Event ID 5144: Network share deleted

A network share object was deletedSecurity event 5144 records the removal of a network share, with the account that deleted it and the share's name and path. Often a cleanup step.
5144
Event ID
5144
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Network shares
Default logging
Needs configuration

What event 5144 means

Event 5144 is written on the computer where a share is removed (net share NAME /delete, Remove-SmbShare, Explorer or a remote API call). It carries the same fields as 5142: the account and logon session that made the change, the share name and the local path it exposed.

On its own the event is mostly administrative. Its value comes from pairing it with 5142: a share that existed for a few minutes or hours, was accessed from other hosts (5140) and then deleted, fits the pattern of temporary staging or tool distribution.

Deleting built-in administrative shares such as ADMIN$ or C$ is unusual; they are recreated at the next Server service restart unless disabled in the registry.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Object Access > Audit File Share (Success). Not audited in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserSidSID of the account that deleted the share.
SubjectUserNameAccount that deleted the share.
SubjectDomainNameDomain or computer name of the account.
SubjectLogonIdLogon session that deleted the share; pivot to 4624 and 4688 for context.
ShareNameDeleted share name in the form \\*\NAME.
ShareLocalPathFolder that the share exposed.

Common benign sources

  • Administrators decommissioning shares during file server clean-up or migration.
  • Application uninstallers removing shares they created.

What attackers do that produces it

  • Removing a temporary share used to stage collected data or distribute tools, to reduce traces.
  • Deleting administrative shares on a host to hinder remote administration or response tooling.

Investigation tips

  • Find the matching 5142 for the same ShareName to measure how long the share existed and who created it.
  • Review 5140 and 5145 events on that share during its lifetime to see which hosts and accounts used it.
  • Identify the process that removed the share (net.exe, powershell.exe) through 4688 or Sysmon 1.

MITRE ATT&CK techniques

TechniqueTactics
T1070 Indicator RemovalStealth
T1074 Data StagedCollection

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading