Splunk has removed its deprecated "Network Connection Discovery With Net" analytic and replaced it with "Windows Network Connection Discovery Via Net", updating the detection logic for suspicious use of net.exe and net1.exe on Windows systems. The analytic is designed to surface command-line activity associated with MITRE ATT&CK T1049, which covers adversary reconnaissance of active network connections, open ports, sessions, and reachable resources after initial compromise.
MITRE documents T1049 as a common post-compromise behavior used by APT groups, ransomware operators, and malware families to map local network connectivity through utilities such as netstat, net use, and net session, as well as Windows networking APIs. Splunk said the detection relies on telemetry including Sysmon Event ID 1, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 normalized into the Splunk Endpoint data model, and noted that while the activity can indicate reconnaissance supporting lateral movement or data exfiltration, administrators may also trigger it during legitimate troubleshooting.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the hunting detection "Network Connection Discovery With Net" from its content library, stating it is no longer maintained or supported because it was renamed and its logic was updated. Splunk identified the replacement as "Windows Network Connection Discovery Via Net."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.