LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. CitationMicrosoft Net Utility

Net has a great deal of functionality, CitationSavill 1999 much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

EnterpriseS0039ToolObject v2.8Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Net is a built-in Windows command-line utility for managing users, groups, services, and network connections. Its business significance is that legitimate administration and adversary activity can look very similar: the same utility used by IT can support discovery, service interaction, and lateral movement via SMB/Windows Admin Shares using commands such as net use. Because many ATT&CK-listed groups and one campaign are related to use of this tool, organizations should treat Net activity as a coverage validation problem, not as inherently malicious by itself.

Executive priority

Prioritize visibility and governance around Windows administrative command execution. Net matters because it can affect identity administration, service control, and network connections—areas tied directly to operational resilience and incident scoping. Leaders should ask whether SOC and IR teams can distinguish expected administrator use from unusual use across endpoints, accounts, and network shares, and whether that evidence is retained well enough for investigations and audit support.

Technical view

For Windows environments, validate monitoring of net.exe and net1.exe execution, including command-line arguments, parent process, user context, host role, and remote share or service interaction where available. ATT&CK provides no official detection guidance for this object, so detections should be environment-driven: baseline normal administrative use, then alert on unusual account, host, timing, parent process, or target patterns. Relationship context shows use by numerous groups and campaign C0026, so detections should focus on behavior and context rather than attribution.

Likely telemetry

  • Windows process creation events for net.exe and net1.exe
  • Command-line arguments, including user, group, service, and net use activity
  • Parent process and initiating user/account context
  • Endpoint and host role context for administrative workstations, servers, and domain systems
  • Authentication and network connection evidence associated with SMB/Windows Admin Shares

Detection direction

  • Do not alert on Net execution alone; it is a legitimate Windows utility and likely common in administration.
  • Baseline expected administrator, helpdesk, service account, and automation usage before tuning high-severity alerts.
  • Prioritize anomalous net use activity involving unusual source hosts, destination systems, credentials, or administrative shares.
  • Correlate Net execution with authentication events, SMB connections, service changes, and other discovery activity when available.
  • Include net1.exe in detection logic because the official description notes it may be executed by net.exe and can be used directly.

Mitigation priorities

  • Establish least-privilege administrative practices for Windows accounts that can manage users, groups, services, and remote connections.
  • Limit and monitor administrative share and SMB access according to business need.
  • Separate routine administration from user workstations where practical, so Net activity from unexpected endpoints is easier to triage.
  • Ensure endpoint logging or EDR captures command-line execution for both net.exe and net1.exe.
  • Document approved administrative use cases to support SOC tuning, IR scoping, and compliance evidence.
Additional notes and limits

This object is a tool entry, not a technique, and ATT&CK does not specify tactics for the object field even though the official description cites Discovery, SMB/Windows Admin Shares lateral movement via net use, and service interaction as adversary-relevant uses. The many related groups and campaign demonstrate broad historical reporting around Net use, but local detection should remain behavior-based.

No official ATT&CK detection text is provided. The supplied fields do not support claims of current exploitation, guaranteed detectability, non-Windows platforms, or specific vendor controls. Local baselines, logging configuration, and administrative workflows are required to determine what is suspicious.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. CitationMicrosoft Net Utility

Net has a great deal of functionality, CitationSavill 1999 much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.8
Created
Modified
Raw hash
c98a12b750b7d44f...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.