Net is the Windows command-line utility used for administrative operations across local systems and Active Directory environments. In intrusion activity it is commonly abused as a dual-use tool rather than malware in its own right. It supports discovery of remote systems, network shares, domain users, and domain groups through commands such as those used for share enumeration, account discovery, and group discovery. It can also manipulate accounts and groups, including creation of local or domain accounts when privileges permit, and can start or stop Windows services for execution or service control. Because it is native to Windows and widely available, Net is frequently used by threat actors and post-exploitation workflows for reconnaissance, account manipulation, lateral movement preparation, and operational execution while blending with legitimate administration. It primarily targets Windows enterprise environments, especially domain-joined systems and Active Directory networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The net start and net stop commands can be used in Net to execute or stop Windows services.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Net ... Account Manipulation: Additional Local or Domain Groups
Cobalt Strike ... System Service Discovery; ... Net ... System Service Discovery
During the 2015 Ukraine Electric Power Attack, Sandworm Team remotely discovered systems over LAN connections. OT systems were visible from the IT network as well, giving adversaries the ability to discover operational assets.
Cobalt Strike ... System Network Connections Discovery; ... Net ... System Network Connections Discovery; ... netstat ... System Network Connections Discovery
Cobalt Strike ... Permission Groups Discovery: Local Groups; ... Net ... Permission Groups Discovery: Local Groups
Brute Ratel C4 can use LDAP queries, net group "Domain Admins" /domain and net user /domain for discovery. OilRig has run net group "domain admins" /domain and net group "Exchange Trusted Subsystem" /domain to get account listings on a victim. Wizard Spider has identified domain admins through the use of net group "Domain admins" /DOMAIN.
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Built-in Windows utility abused to find shared drives and directories on remote and local systems.
A built-in Windows utility whose domain-related commands can gather and manipulate domain account information.
A native Windows utility whose commands such as net view are used to gather information about remote systems.
Windows built-in utility (net.exe) used to enumerate shares (net view/net share).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.