Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

ID: S0039
Associated Software: net.exe
Type: TOOL
Platforms: Windows
Contributors: David Ferguson, CyberSponse
Version: 2.0

Techniques Used

Domain ID Name Use
Enterprise T1087 Account Discovery Commands under net user can be used in Net to gather information about and manipulate user accounts.[2]
Enterprise T1136 Create Account The net user username \password and net user username \password \domain commands in Net can be used to create a local or domain account respectively.[2]
Enterprise T1126 Network Share Connection Removal The net use \\system\share /delete command can be used in Net to remove an established connection to a network share.[3]
Enterprise T1135 Network Share Discovery The net view \\remotesystem and net share commands in Net can be used to find shared drives and directories on remote and local systems respectively.[2]
Enterprise T1201 Password Policy Discovery The net accounts and net accounts /domain commands with Net can be used to obtain password policy information.[2]
Enterprise T1069 Permission Groups Discovery Commands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.[2]
Enterprise T1018 Remote System Discovery Commands such as net view can be used in Net to gather information about available remote systems.[2]
Enterprise T1035 Service Execution The net start and net stop commands can be used in Net to execute or stop Windows services.[2]
Enterprise T1049 System Network Connections Discovery Commands such as net use and net session can be used in Net to gather information about network connections from a particular host.[2]
Enterprise T1007 System Service Discovery The net start command can be used in Net to find information about Windows services.[2]
Enterprise T1124 System Time Discovery The net time command can be used in Net to determine the local or remote system time.[4]
Enterprise T1077 Windows Admin Shares Lateral movement can be done with Net through net use commands to connect to the on remote systems.[2]

Groups

Groups that use this software:

admin@338
APT1
APT32
APT33
APT38
BRONZE BUTLER
Deep Panda
Dragonfly 2.0
FIN8
Ke3chang
Leviathan
menuPass
Naikon
OilRig
Orangeworm
Soft Cell
Threat Group-1314
Threat Group-3390
Turla

References