The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

ID: S0039
Associated Software: net.exe

Type: TOOL
Contributors: David Ferguson, CyberSponse

Platforms: Windows

Version: 2.0

Techniques Used

EnterpriseT1087Account DiscoveryCommands under net user can be used in Net to gather information about and manipulate user accounts.[2]
EnterpriseT1136Create AccountThe net user username \password and net user username \password \domain commands in Net can be used to create a local or domain account respectively.[2]
EnterpriseT1126Network Share Connection RemovalThe net use \\system\share /delete command can be used in Net to remove an established connection to a network share.[3]
EnterpriseT1135Network Share DiscoveryThe net view \\remotesystem and net share commands in Net can be used to find shared drives and directories on remote and local systems respectively.[2]
EnterpriseT1201Password Policy DiscoveryThe net accounts and net accounts /domain commands with Net can be used to obtain password policy information.[2]
EnterpriseT1069Permission Groups DiscoveryCommands such as net group and net localgroup can be used in Net to gather information about and manipulate groups.[2]
EnterpriseT1018Remote System DiscoveryCommands such as net view can be used in Net to gather information about available remote systems.[2]
EnterpriseT1035Service ExecutionThe net start and net stop commands can be used in Net to execute or stop Windows services.[2]
EnterpriseT1049System Network Connections DiscoveryCommands such as net use and net session can be used in Net to gather information about network connections from a particular host.[2]
EnterpriseT1007System Service DiscoveryThe net start command can be used in Net to find information about Windows services.[2]
EnterpriseT1124System Time DiscoveryThe net time command can be used in Net to determine the local or remote system time.[4]
EnterpriseT1077Windows Admin SharesLateral movement can be done with Net through net use commands to connect to the on remote systems.[2]


Groups that use this software:

Deep Panda
Dragonfly 2.0
Threat Group-1314
Threat Group-3390