If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/software/S0039 - Net, Software S0039 | MITRE AT.

site address: attack.mitre.org/software/S0039 redirected to: attack.mitre.org/software/S0039

site title: Net, Software S0039 MITRE ATT&CK®

Our opinion (on Monday 24 August 2026 11:30:38 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

net, techniques, used, groups, that, use, this, software, campaigns, references, enterprise, layer,

Text of the page (most frequently used words):
retrieved (55), net (53), and (37), the (35), #enterprise (20), october (20), used (20), 2020 (18), can (18), commands (16), may (15), group (13), threat (13), domain (13), 2024 (13), groups (12), 2017 (12), att (11), 2018 (11), 2019 (11), discovery (11), account (11), all (10), system (10), use (9), team (9), july (9), november (9), ransomware (9), information (9), 2023 (8), 2016 (8), august (8), march (8), april (8), 2021 (8), microsoft (8), windows (8), local (8), about (8), 2015 (7), attack (7), targets (7), june (7), with (7), services (7), operation (7), december (7), network (7), campaigns (6), software (6), techniques (6), january (6), ryuk (6), 2014 (6), september (6), for (6), remote (6), such (6), gather (6), user (6), ics (5), mobile (5), none (5), february (5), new (5), espionage (5), dfir (5), report (5), cloud (5), cyber (5), systems (5), exe (5), 002 (5), share (5), 2026 (4), mitre (4), counter (4), unit (4), research (4), bronze (4), campaign (4), storm (4), 0501 (4), time (4), utility (4), command (4), manipulate (4), password (4), accounts (4), create (4), version (4), policy (3), reference (3), cti (3), data (3), defenses (3), tactics (3), turla (3), security (3), organizations (3), using (3), has (3), start (3), targeted (3), chinese (3), cisa (3), against (3), intelligence (3), 2025 (3), attacks (3), china (3), government (3), naikon (3), localgroup (3), operating (3), name (3), admin (3), connections (3), view (3), 001 (3), corporation (2), are (2), domains (2), resources (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), matrices (2), core (2), objects (2), elovitz (2), your (2), response (2), investigation (2), saudi (2), cyberespionage (2), exploit (2), 2022 (2), access (2), shilko (2), actor (2), that (2), healthcare (2), hours (2), run (2), ransom (2), special (2), one (2), operations (2), inc (2), pulse (2), updates (2), apt (2), actors (2), russian (2), global (2), compromise (2), environments (2), toddycat (2), deep (2), targeting (2), butler (2), japanese (2), mirrorface (2), under (2), ta505 (2), other (2), based (2), analysis (2), apt1 (2), ke3chang (2), symantec (2), orangeworm (2), middle (2), oilrig (2), from (2), critical (2), infrastructure (2), apt41 (2), fireeye (2), apt38 (2), references (2), c0026 (2), stop (2), service (2), find (2), through (2), smb (2), shares (2), permission (2), connection (2), removal (2), username (2), users (2), s0039 (2), functionality (2), net1 (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, sub, hawley, galaxy, opportunity, ahl, know, enemy, financially, motivated, spear, phishing, elfin, relentless, multiple, arabia, union, persists, despite, disclosures, exchange, leads, wide, apt35, automates, initial, proxyshell, fin12, prolific, intrusion, aggressively, pursued, sean, gallagher, peter, mackenzie, elida, leite, syed, shahram, bill, kearney, anand, aijan, sivagnanam, suraj, mundalik, they, back, inside, speed, return, kimberly, goody, jeremy, kennelly, joshua, steve, douglas, bienstock, unhappy, hour, kegtap, singlemalt, chaser, brian, donohue, katie, nickels, paul, michaud, adina, bodkins, taylor, chapman, tony, lambert, jeff, felling, kyle, rainey, mike, haag, matt, graeber, aaron, didier, bazar, how, hospital, thwarted, outbreak, hanel, big, game, hunting, another, lucrative, dell, secureworks, living, off, land, carvey, lolbin, perez, checking, compromising, secure, vpn, devices, nsa, fbi, ncsc, gru, conducting, brute, force, dedola, keep, calm, check, logs, alperovitch, thought, national, think, tanks, enterprises, tomonaga, organisations, jansen, abusing, fly, radar, mar, 10296782, sorefang, hiroaki, shifting, breaking, down, html, rats, latest, evolving, lead, expanding, hybrid, kaspersky, lab, epic, solving, some, mysteries, snake, uroburos, plan, apt40, examining, nexus, mandiant, exposing, units, smallridge, apt15, alive, strong, royalcli, royaldns, villeneuve, bennett, moran, haq, scott, geers, ministries, foreign, affairs, sector, europe, asia, hunter, crambus, eastern, sardiwal, east, apt34, suspected, iranian, cve, 11882, falcone, lee, arabian, deliver, helminth, backdoor, joe, slowik, anatomy, detecting, defeating, crashoverride, vrabie, traces, military, baumgartner, golovkin, msnmm, earliest, dahan, cobalt, kitty, pwc, bae, hopper, technical, annex, cert, alert, ta18, 074a, activity, energy, sectors, fraser, double, dragonapt41, dual, crime, prc, state, sponsored, maintain, persistent, silhouette, defense, uses, dropbox, malware, communications, hong, kong, media, outlets, cybereason, nocturnus, soft, cell, worldwide, telecommunications, providers, usual, suspects, savill, 1999, 2006, description, fin8, g0061, apt33, g0064, 3390, g0027, magic, hound, g0059, wizard, spider, g0102, 1314, g0028, g1032, apt5, g1023, apt28, g0007, g1022, panda, g0009, g0060, g1054, chimera, g0114, apt29, g0016, g0092, g1053, g0010, leviathan, g0065, g0006, g0004, g0071, g0049, sandworm, g0034, g0019, apt32, g0050, menupass, g0045, dragonfly, g0035, g0096, volt, typhoon, g1017, 338, g0018, gallium, g0093, g0082, this, determine, t1124, execute, execution, t1569, t1007, particular, host, session, t1049, available, t1018, lateral, movement, done, connect, t1021, t1069, obtain, t1201, shared, drives, directories, respectively, remotesystem, t1135, remove, established, delete, indicator, 005, t1070, t1136, add, existing, additional, manipulation, 007, t1098, flag, current, t1087, download, layer, navigator, layers, live, permalink, last, modified, created, david, ferguson, cybersponse, contributors, platforms, tool, type, associated, great, deal, much, which, useful, adversary, gathering, moving, laterally, interacting, executed, certain, when, directly, component, line, control, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, history, engage, tools, advisory, council, learn, more, get, started, detections,


Text of the page (random words):
net software s0039 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software net net the net utility is a component of the windows operating system it is used in command line operations for control of users groups services and network connections 1 net has a great deal of functionality 2 much of which is useful for an adversary such as gathering system and network information for discovery moving laterally through smb windows admin shares using net use commands and interacting with services the net1 exe utility is executed for certain functionality when net exe is run and can be used directly in commands such as net1 user id s0039 ⓘ associated software net exe ⓘ type tool ⓘ platforms windows contributors david ferguson cybersponse version 2 8 created 31 may 2017 last modified 12 may 2026 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1087 001 account discovery local account commands under net user can be used in net to gather information about and manipulate user accounts 2 002 account discovery domain account net commands used with the domain flag can be used to gather information about and manipulate user accounts on the current domain 3 enterprise t1098 007 account manipulation additional local or domain groups the net localgroup and net group commands in net can be used to add existing users to local and domain groups 4 5 enterprise t1136 001 create account local account the net user username password commands in net can be used to create a local account 2 002 create account domain account the net user username password domain commands in net can be used to create a domain account 2 enterprise t1070 005 indicator removal network share connection removal the net use system share delete command can be used in net to remove an established connection to a network share 6 enterprise t1135 network share discovery the net view remotesystem and net share commands in net can be used to find shared drives and directories on remote and local systems respectively 2 enterprise t1201 password policy discovery the net accounts and net accounts domain commands with net can be used to obtain password policy information 2 enterprise t1069 001 permission groups discovery local groups commands such as net group and net localgroup can be used in net to gather information about and manipulate groups 2 002 permission groups discovery domain groups commands such as net group domain can be used in net to gather information about and manipulate groups 2 enterprise t1021 002 remote services smb windows admin shares lateral movement can be done with net through net use commands to connect to the on remote systems 2 enterprise t1018 remote system discovery commands such as net view can be used in net to gather information about available remote systems 2 enterprise t1049 system network connections discovery commands such as net use and net session can be used in net to gather information about network connections from a particular host 2 enterprise t1007 system service discovery the net start command can be used in net to find information about windows services 2 enterprise t1569 002 system services service execution the net start and net stop commands can be used in net to execute or stop windows services 2 enterprise t1124 system time discovery the net time command can be used in net to determine the local or remote system time 7 groups that use this software id name references g0082 apt38 8 g0093 gallium 9 g0018 admin 338 10 g1017 volt typhoon 11 12 g0096 apt41 13 g0035 dragonfly 14 g0045 menupass 15 g0050 apt32 16 g0019 naikon 17 18 g0034 sandworm team 19 g0049 oilrig 20 21 22 g0071 orangeworm 23 g0004 ke3chang 24 25 g0006 apt1 26 g0065 leviathan 27 g0010 turla 28 g1053 storm 0501 storm 0501 has used the net utility on the windows operating system 29 30 g0092 ta505 31 g0016 apt29 32 g0114 chimera 33 g1054 mirrorface 34 g0060 bronze butler 35 g0009 deep panda 36 g1022 toddycat 37 g0007 apt28 38 g1023 apt5 39 g1032 inc ransom 40 g0028 threat group 1314 41 g0102 wizard spider 42 43 44 45 46 47 48 49 g0059 magic hound 50 51 g0027 threat group 3390 52 g0064 apt33 53 g0061 fin8 54 campaigns id name description c0026 c0026 55 references microsoft 2006 october 18 net exe utility retrieved september 22 2015 savill j 1999 march 4 net exe reference retrieved september 22 2015 microsoft 2017 february 14 net commands on windows operating systems retrieved march 19 2020 microsoft 2016 august 31 net localgroup retrieved august 5 2024 microsoft 2016 august 31 net group retrieved august 5 2024 microsoft n d net use retrieved november 25 2016 microsoft n d net time retrieved november 25 2016 fireeye 2018 october 03 apt38 un usual suspects retrieved november 17 2024 cybereason nocturnus 2019 june 25 operation soft cell a worldwide campaign against telecommunications providers retrieved july 18 2019 fireeye threat intelligence 2015 december 1 china based cyber threat group uses dropbox for malware communications and targets hong kong media outlets retrieved december 4 2015 counter threat unit research team 2023 may 24 chinese cyberespionage group bronze silhouette targets u s government and defense organizations retrieved july 27 2023 cisa et al 2024 february 7 prc state sponsored actors compromise and maintain persistent access to u s critical infrastructure retrieved may 15 2024 fraser n et al 2019 august 7 double dragonapt41 a dual espionage and cyber crime operation apt41 retrieved september 23 2019 us cert 2018 march 16 alert ta18 074a russian government cyber activity targeting energy and other critical infrastructure sectors retrieved june 6 2018 pwc and bae systems 2017 april operation cloud hopper technical annex retrieved april 13 2017 dahan a 2017 operation cobalt kitty retrieved december 27 2018 baumgartner k golovkin m 2015 may the msnmm campaigns the earliest naikon apt campaigns retrieved april 10 2019 vrabie v 2021 april 23 naikon traces from a military cyber espionage operation retrieved june 29 2021 joe slowik 2018 october 12 anatomy of an attack detecting and defeating crashoverride retrieved december 18 2020 falcone r and lee b 2016 may 26 the oilrig campaign attacks on saudi arabian organizations deliver helminth backdoor retrieved may 3 2017 sardiwal m et al 2017 december 7 new targeted attack in the middle east by apt34 a suspected iranian threat group using cve 2017 11882 exploit retrieved december 20 2017 symantec threat hunter team 2023 october 19 crambus new campaign targets middle eastern government retrieved november 27 2024 symantec security response attack investigation team 2018 april 23 new orangeworm attack group targets the healthcare sector in the u s europe and asia retrieved may 8 2018 villeneuve n bennett j t moran n haq t scott m geers k 2014 operation ke3chang targeted attacks against ministries of foreign affairs retrieved november 12 2014 smallridge r 2018 march 10 apt15 is alive and strong an analysis of royalcli and royaldns retrieved april 4 2018 mandiant n d apt1 exposing one of china s cyber espionage units retrieved july 18 2016 plan f et al 2019 march 4 apt40 examining a china nexus espionage actor retrieved march 18 2019 kaspersky lab s global research and analysis team 2014 august 7 the epic turla operation solving some of the mysteries of snake uroburos retrieved december 11 2014 microsoft threat intelligence 2024 september 26 storm 0501 ransomware attacks expanding to hybrid cloud environments retrieved october 19 2025 microsoft threat intelligence 2025 august 27 storm 0501 s evolving techniques lead to cloud based ransomware retrieved october 19 2025 hiroaki h and lu l 2019 june 12 shifting tactics breaking down ta505 group s use of html rats and other techniques in latest campaigns retrieved may 29 2020 cisa 2020 july 16 mar 10296782 1 v1 sorefang retrieved september 29 2020 jansen w 2021 january 12 abusing cloud services to fly under the radar retrieved september 12 2024 tomonaga s 2024 july 16 mirrorface attack against japanese organisations retrieved april 17 2026 counter threat unit research team 2017 october 12 bronze butler targets japanese enterprises retrieved january 4 2018 alperovitch d 2014 july 7 deep in thought chinese targeting of national security think tanks retrieved november 12 2014 dedola g et al 2023 october 12 toddycat keep calm and check logs retrieved january 3 2024 nsa cisa fbi ncsc 2021 july russian gru conducting global brute force campaign to compromise enterprise and cloud environments retrieved july 26 2021 perez d et al 2021 may 27 re checking your pulse updates on chinese apt actors compromising pulse secure vpn devices retrieved february 5 2024 carvey h 2024 may 1 lolbin to inc ransomware retrieved june 5 2024 dell secureworks counter threat unit special operations team 2015 may 28 living off the land retrieved january 26 2016 hanel a 2019 january 10 big game hunting with ryuk another lucrative targeted ransomware retrieved may 12 2020 brian donohue katie nickels paul michaud adina bodkins taylor chapman tony lambert jeff felling kyle rainey mike haag matt graeber aaron didier 2020 october 29 a bazar start how one hospital thwarted a ryuk ransomware outbreak retrieved october 30 2020 kimberly goody jeremy kennelly joshua shilko steve elovitz douglas bienstock 2020 october 28 unhappy hour special kegtap and singlemalt with a ransomware chaser retrieved october 28 2020 the dfir report 2020 october 8 ryuk s return retrieved october 9 2020 the dfir report 2020 november 5 ryuk speed run 2 hours to ransom retrieved november 6 2020 the dfir report 2020 october 18 ryuk in 5 hours retrieved october 19 2020 sean gallagher peter mackenzie elida leite syed shahram bill kearney anand aijan sivagnanam gn suraj mundalik 2020 october 14 they re back inside a new ryuk ransomware attack retrieved october 14 2020 shilko j et al 2021 october 7 fin12 the prolific ransomware intrusion threat actor that has aggressively pursued healthcare targets retrieved june 15 2023 dfir report 2022 march 21 apt35 automates initial access using proxyshell retrieved may 25 2022 dfir report 2021 november 15 exchange exploit leads to domain wide ransomware retrieved january 5 2023 counter threat unit research team 2017 june 27 bronze union cyberespionage persists despite disclosures retrieved july 13 2017 security response attack investigation team 2019 march 27 elfin relentless espionage group targets multiple organizations in saudi arabia and u s retrieved april 10 2019 elovitz s ahl i 2016 august 18 know your enemy new financially motivated spear phishing group retrieved february 26 2018 hawley s et al 2023 february 2 turla a galaxy of opportunity retrieved may 15 2023 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 100 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/software/S0039
X-GitHub-Request-Id ABB6:15BD:8ACCE18:8BFBC86:6A8C2B5E
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Mon, 24 Aug 2026 11:30:38 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290040-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787571038.064145,VS0,VE98
Vary Accept-Encoding
X-Fastly-Request-ID 87f98d84593aa8446a0208e652bfd97899360dbf
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/software/S0039/
access-control-allow-origin *
expires Mon, 24 Aug 2026 11:40:38 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 63EE:34F8D5:C10AC2:CA57FE:6A8C2B5D
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 11:30:38 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630022-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787571038.186594,VS0,VE92
vary Accept-Encoding
x-fastly-request-id 349f643d5718bc7d716297bfe498b2cafb8d713e
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-1dc3f
expires Mon, 24 Aug 2026 11:40:38 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 7928:9B535:BF5E20:C8AAFF:6A8C2B59
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Mon, 24 Aug 2026 11:30:38 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630022-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787571038.286458,VS0,VE93
vary Accept-Encoding
x-fastly-request-id 267e7f5fad49e1008070f5e75e70a739b2511996
content-length 20630

Meta Tags

title="Net, Software S0039 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size20630
load time (s)0.589076
redirect count2
speed download35025
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"