Net
MITRE ATT&CK: S0039 View on attack.mitre.org
Aliases: net.exe, Net
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:32:30
Context
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. Net has a great deal of functionality, much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
Detection coverage
- 200 Sigma rules
Malware & tools used
- Domain Groups (attack-pattern)
- System Time Discovery (attack-pattern)
- Domain Account (attack-pattern)
- Local Account (attack-pattern)
- System Service Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Network Share Connection Removal (attack-pattern)
- Service Execution (attack-pattern)
- Local Account (attack-pattern)
- Additional Local or Domain Groups (attack-pattern)
- Local Groups (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Domain Account (attack-pattern)
- Password Policy Discovery (attack-pattern)
Used by threat actors
- C0026 (campaign)
- Threat Group-3390 (threat-actor)
- Threat Group-1314 (threat-actor)
- BRONZE BUTLER (threat-actor)
- Deep Panda (threat-actor)
- Wizard Spider (threat-actor)
- Sandworm Team (threat-actor)
- Magic Hound (threat-actor)
- Volt Typhoon (threat-actor)
- INC Ransom (threat-actor)
- Storm-0501 (threat-actor)
- APT1 (threat-actor)
- Turla (threat-actor)
- APT32 (threat-actor)
- TA505 (threat-actor)
- APT28 (threat-actor)
- Ke3chang (threat-actor)
- APT29 (threat-actor)
- admin@338 (threat-actor)
- APT41 (threat-actor)
- FIN8 (threat-actor)
- Orangeworm (threat-actor)
- Naikon (threat-actor)
- APT38 (threat-actor)
- APT33 (threat-actor)
Reports & references
- MITRE ATT&CK — S0039 (report)
- Microsoft — Aa939914 (report)
- web.archive.org — Netexe Reference (report)