MITRE ATT&CK documents widespread adversary use of the Windows net localgroup command—particularly net localgroup administrators—to enumerate local groups and identify accounts with local administrator privileges after compromise. The technique, tracked as T1069.001 (Permission Groups Discovery: Local Groups), appears across numerous intrusion sets and malware families, including OilRig, Turla, Volt Typhoon, Tonto Team, Chimera, and HEXANE, and is also supported by offensive tooling such as BloodHound, Cobalt Strike, PoshC2, and SILENTTRINITY.
Splunk has removed its legacy Net Localgroup Discovery analytic, which detected execution of net localgroup through EDR process telemetry, and replaced it with Windows Group Discovery Via Net (UUID c5c8e0f3-147a-43da-bf04-4cfaec27dc44). The retired rule had been aligned to ATT&CK T1069.001 and was intended to surface attacker reconnaissance that can enable privilege escalation and lateral movement, underscoring continued defender focus on monitoring local group enumeration on Windows systems.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk removed the hunting detection 'Net Localgroup Discovery' from its Threat Research content library, stating it is no longer maintained or supported. The company said the analytic was deprecated in favor of the replacement detection 'Windows Group Discovery Via Net' (UUID c5c8e0f3-147a-43da-bf04-4cfaec27dc44).
MITRE ATT&CK documents the Local Groups Discovery sub-technique T1069.001, including examples of threat actors, malware, and tools using commands such as `net localgroup administrators` to enumerate local groups and privileged accounts on compromised systems.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.