Windows Process Creation: Execution of Net.exe or Net1.exe

Alerts on execution of net.exe/net1.exe with common net subcommands via Windows process creation and command-line telemetry.

FreeReviewedSigma · Low · v5
Product
windows
Category
process_creation
Author
Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements) (SigmaHQ), DRL 1.1
Published
2019-01-16
Updated
2026-07-31

ATT&CK techniques

Discovery → Lateral Movement

What it detects

This rule flags Windows process creation events where the executable path ends with net.exe or net1.exe and the command line contains common net.exe subcommands (for accounts, group/localgroup, share, start/stop, user, or view). Attackers and administrators may use net.exe for discovery and interaction with local services, users, and shares, so monitoring these invocations can help surface suspicious activity patterns. The detection relies on process creation telemetry including Image (path) and OriginalFileName, along with CommandLine content.

Related detections9 linkedT1069.002 — drag to rearrange
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows file creation for SharpHound/BloodHound collection output filenames
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Suspicious Group Discovery - Command (via process_creation)
Suspicious Active Directory Enumeration via ADWS PowerShell Cmdlets via ps_script
Windows Process Creation: Renamed AdFind.exe Executions
Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Windows Process Creation: Execution of Net.exe or Net1.exe
Pivot detection · T1069.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.