Suspicious Group And Account Reconnaissance Activity Using Net.EXE — Detection Rule
Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)