The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1136 | .001 | 创建账户: Local Account |
The |
| .002 | 创建账户: Domain Account |
The |
||
| Enterprise | T1201 | 密码策略发现 |
The |
|
| Enterprise | T1069 | .001 | 权限组发现: Local Groups |
Commands such as |
| .002 | 权限组发现: Domain Groups |
Commands such as |
||
| Enterprise | T1070 | .005 | 移除指标: Network Share Connection Removal |
The |
| Enterprise | T1124 | 系统时间发现 |
The |
|
| Enterprise | T1569 | .002 | 系统服务: Service Execution |
The |
| Enterprise | T1007 | 系统服务发现 |
The |
|
| Enterprise | T1049 | 系统网络连接发现 |
Commands such as |
|
| Enterprise | T1135 | 网络共享发现 |
The |
|
| Enterprise | T1087 | .001 | 账号发现: Local Account |
Commands under |
| .002 | 账号发现: Domain Account |
Net commands used with the |
||
| Enterprise | T1098 | .007 | 账号操控: Additional Local or Domain Groups |
The |
| Enterprise | T1021 | .002 | 远程服务: SMB/Windows Admin Shares |
Lateral movement can be done with Net through |
| Enterprise | T1018 | 远程系统发现 |
Commands such as |
|