Windows Process Creation: Execution of Net.exe or Net1.exe
Alerts on execution of net.exe/net1.exe with common net subcommands via Windows process creation and command-line telemetry.
- Product
- windows
- Category
- process_creation
- Author
- Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements) (SigmaHQ), DRL 1.1
- Published
- 2019-01-16
- Updated
- 2026-07-31
ATT&CK techniques
Discovery → Lateral MovementRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process creation events where the executable path ends with net.exe or net1.exe and the command line contains common net.exe subcommands (for accounts, group/localgroup, share, start/stop, user, or view). Attackers and administrators may use net.exe for discovery and interaction with local services, users, and shares, so monitoring these invocations can help surface suspicious activity patterns. The detection relies on process creation telemetry including Image (path) and OriginalFileName, along with CommandLine content.
Reporting behind it
- pentest.bloghttps://pentest.blog/windows-privilege-escalation-methods-for-pentesters/
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/4d2e7fc1-af0b-4915-89aa-03d25ba7805e.html
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/e61f557c-a9d0-4c25-ab5b-bbc46bb24deb.html
- eqllib.readthedocs.iohttps://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1007/T1007.md#atomic-test-2---system-service-discovery---netexe
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_net_execution.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Execution of Net.exe or Net1.exe"
id: 187c433e-534a-4710-974b-f535d5d2c977
status: test
description: This rule flags Windows process creation events where the executable path ends with net.exe or net1.exe and the command line contains common net.exe subcommands (for accounts, group/localgroup, share, start/stop, user, or view). Attackers and administrators may use net.exe for discovery and interaction with local services, users, and shares, so monitoring these invocations can help surface suspicious activity patterns. The detection relies on process creation telemetry including Image (path) and OriginalFileName, along with CommandLine content.
references:
- https://pentest.blog/windows-privilege-escalation-methods-for-pentesters/
- https://eqllib.readthedocs.io/en/latest/analytics/4d2e7fc1-af0b-4915-89aa-03d25ba7805e.html
- https://eqllib.readthedocs.io/en/latest/analytics/e61f557c-a9d0-4c25-ab5b-bbc46bb24deb.html
- https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1007/T1007.md#atomic-test-2---system-service-discovery---netexe
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_net_execution.yml
author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements), Huntrule Team
date: 2019-01-16
modified: 2022-07-11
tags:
- attack.discovery
- attack.t1007
- attack.t1049
- attack.t1018
- attack.t1135
- attack.t1201
- attack.t1069.001
- attack.t1069.002
- attack.t1087.001
- attack.t1087.002
- attack.lateral-movement
- attack.t1021.002
- attack.s0039
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \net.exe
- \net1.exe
- OriginalFileName:
- net.exe
- net1.exe
selection_cli:
CommandLine|contains:
- " accounts"
- " group"
- " localgroup"
- " share"
- " start"
- " stop "
- " user"
- " view"
condition: all of selection_*
falsepositives:
- Likely
level: low
license: DRL-1.1
related:
- id: 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
type: derived