Event ID 5144: Network share deleted
- Event ID
- 5144
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Network shares
- Default logging
- Needs configuration
What event 5144 means
Event 5144 is written on the computer where a share is removed (net share NAME /delete, Remove-SmbShare, Explorer or a remote API call). It carries the same fields as 5142: the account and logon session that made the change, the share name and the local path it exposed.
On its own the event is mostly administrative. Its value comes from pairing it with 5142: a share that existed for a few minutes or hours, was accessed from other hosts (5140) and then deleted, fits the pattern of temporary staging or tool distribution.
Deleting built-in administrative shares such as ADMIN$ or C$ is unusual; they are recreated at the next Server service restart unless disabled in the registry.
When it is logged
Advanced Audit Policy Configuration > Object Access > Audit File Share (Success). Not audited in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserSid | SID of the account that deleted the share. |
| SubjectUserName | Account that deleted the share. |
| SubjectDomainName | Domain or computer name of the account. |
| SubjectLogonId | Logon session that deleted the share; pivot to 4624 and 4688 for context. |
| ShareName | Deleted share name in the form \\*\NAME. |
| ShareLocalPath | Folder that the share exposed. |
Common benign sources
- Administrators decommissioning shares during file server clean-up or migration.
- Application uninstallers removing shares they created.
What attackers do that produces it
- Removing a temporary share used to stage collected data or distribute tools, to reduce traces.
- Deleting administrative shares on a host to hinder remote administration or response tooling.
Investigation tips
- Find the matching 5142 for the same
ShareNameto measure how long the share existed and who created it. - Review 5140 and 5145 events on that share during its lifetime to see which hosts and accounts used it.
- Identify the process that removed the share (
net.exe,powershell.exe) through 4688 or Sysmon 1.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.