Net

MITRE ATT&CK: S0039 View on attack.mitre.org

Aliases: net.exe, Net

Operating systems
windows
Profile updated
2026-07-07 15:32:30

Context

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. Net has a great deal of functionality, much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Detection coverage

  • 200 Sigma rules

Malware & tools used

  • Domain Groups (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Local Account (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Network Share Connection Removal (attack-pattern)
  • Service Execution (attack-pattern)
  • Local Account (attack-pattern)
  • Additional Local or Domain Groups (attack-pattern)
  • Local Groups (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Domain Account (attack-pattern)
  • Password Policy Discovery (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0039 (report)
  • Microsoft — Aa939914 (report)
  • web.archive.org — Netexe Reference (report)

External references