Suspicious Group And Account Reconnaissance Activity Using Net.EXE — Detection Rule

Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)

Read the full analysis on IntelFusions