S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. CitationMicrosoft Net Utility
Net has a great deal of functionality, CitationSavill 1999 much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
Security context for executives and security teams
Net is a built-in Windows command-line utility for managing users, groups, services, and network connections. Its business significance is that legitimate administration and adversary activity can look very similar: the same utility used by IT can support discovery, service interaction, and lateral movement via SMB/Windows Admin Shares using commands such as net use. Because many ATT&CK-listed groups and one campaign are related to use of this tool, organizations should treat Net activity as a coverage validation problem, not as inherently malicious by itself.
Executive priority
Prioritize visibility and governance around Windows administrative command execution. Net matters because it can affect identity administration, service control, and network connections—areas tied directly to operational resilience and incident scoping. Leaders should ask whether SOC and IR teams can distinguish expected administrator use from unusual use across endpoints, accounts, and network shares, and whether that evidence is retained well enough for investigations and audit support.
Technical view
For Windows environments, validate monitoring of net.exe and net1.exe execution, including command-line arguments, parent process, user context, host role, and remote share or service interaction where available. ATT&CK provides no official detection guidance for this object, so detections should be environment-driven: baseline normal administrative use, then alert on unusual account, host, timing, parent process, or target patterns. Relationship context shows use by numerous groups and campaign C0026, so detections should focus on behavior and context rather than attribution.
Likely telemetry
- Windows process creation events for net.exe and net1.exe
- Command-line arguments, including user, group, service, and net use activity
- Parent process and initiating user/account context
- Endpoint and host role context for administrative workstations, servers, and domain systems
- Authentication and network connection evidence associated with SMB/Windows Admin Shares
Detection direction
- Do not alert on Net execution alone; it is a legitimate Windows utility and likely common in administration.
- Baseline expected administrator, helpdesk, service account, and automation usage before tuning high-severity alerts.
- Prioritize anomalous net use activity involving unusual source hosts, destination systems, credentials, or administrative shares.
- Correlate Net execution with authentication events, SMB connections, service changes, and other discovery activity when available.
- Include net1.exe in detection logic because the official description notes it may be executed by net.exe and can be used directly.
Mitigation priorities
- Establish least-privilege administrative practices for Windows accounts that can manage users, groups, services, and remote connections.
- Limit and monitor administrative share and SMB access according to business need.
- Separate routine administration from user workstations where practical, so Net activity from unexpected endpoints is easier to triage.
- Ensure endpoint logging or EDR captures command-line execution for both net.exe and net1.exe.
- Document approved administrative use cases to support SOC tuning, IR scoping, and compliance evidence.
Additional notes and limits
This object is a tool entry, not a technique, and ATT&CK does not specify tactics for the object field even though the official description cites Discovery, SMB/Windows Admin Shares lateral movement via net use, and service interaction as adversary-relevant uses. The many related groups and campaign demonstrate broad historical reporting around Net use, but local detection should remain behavior-based.
No official ATT&CK detection text is provided. The supplied fields do not support claims of current exploitation, guaranteed detectability, non-Windows platforms, or specific vendor controls. Local baselines, logging configuration, and administrative workflows are required to determine what is suspicious.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. CitationMicrosoft Net Utility
Net has a great deal of functionality, CitationSavill 1999 much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
