Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0039
MITRE ATT&CK Tool

Net (S0039)

net.exe
ShareXLinkedInRedditHN

The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft Net Utility) [Net](https://attack.mitre.org/software/S0039) has a great deal of functionality, (Citation: Savill 1999) much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through [SMB/Windows Admin Shares](https://attack.mitre.org/techniques/T1021/002) using <code>net use</code> commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as <code>net1 user</code>.

Platforms: Windows

▪Techniques implemented (16)

T1201Password Policy DiscoveryT1069.002Domain GroupsT1124System Time DiscoveryT1087.002Domain AccountT1087.001Local AccountT1007System Service DiscoveryT1018Remote System DiscoveryT1135Network Share DiscoveryT1049System Network Connections DiscoveryT1070.005Network Share Connection RemovalT1569.002Service ExecutionT1136.001Local AccountT1098.007Additional Local or Domain GroupsT1069.001Local GroupsT1021.002SMB/Windows Admin SharesT1136.002Domain Account

▪Used by groups (33)

G0082APT38G0093GALLIUMG0018admin@338G1017Volt TyphoonG0096APT41G0035DragonflyG0045menuPassG0050APT32G0019NaikonG0034Sandworm TeamG0049OilRigG0071OrangewormG0004Ke3changG0006APT1G0065LeviathanG0010TurlaG1053Storm-0501G0092TA505G0016APT29G0114ChimeraG1054MirrorFaceG0060BRONZE BUTLERG0009Deep PandaG1022ToddyCatG0007APT28G1023APT5G1032INC RansomG0028Threat Group-1314G0102Wizard SpiderG0059Magic HoundG0027Threat Group-3390G0064APT33G0061FIN8
S0039on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.