Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0039
MITRE ATT&CK Tool

Net (S0039)

net.exe
ShareXLinkedInRedditHN

The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft Net Utility) [Net](https://attack.mitre.org/software/S0039) has a great deal of functionality, (Citation: Savill 1999) much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002) using <code>net use</code> commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as <code>net1 user</code>.

Platforms: Windows

▪Techniques implemented (16)

T1201Password Policy DiscoveryT1069.002Domain GroupsT1124System Time DiscoveryT1087.002Domain AccountT1087.001Local AccountT1007System Service DiscoveryT1018Remote System DiscoveryT1135Network Share DiscoveryT1049System Network Connections DiscoveryT1070.005Network Share Connection RemovalT1569.002Service ExecutionT1136.001Local AccountT1098.007Additional Local or Domain GroupsT1069.001Local GroupsT1021.002SMB/Windows Admin SharesT1136.002Domain Account

▪Used by groups (33)

G1054MirrorFaceG0019NaikonG0059Magic HoundG0082APT38G0035DragonflyG0009Deep PandaG0027Threat Group-3390G0049OilRigG0028Threat Group-1314G0007APT28G0096APT41G0045menuPassG0004Ke3changG0065LeviathanG1023APT5G0071OrangewormG0093GALLIUMG0018admin@338G1032INC RansomG0114ChimeraG0006APT1G0061FIN8G0092TA505G1022ToddyCatG0010TurlaG0064APT33G0102Wizard SpiderG0034Sandworm TeamG0016APT29G0050APT32G1017Volt TyphoonG1053Storm-0501G0060BRONZE BUTLER
S0039on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.