IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

Net command via SYSTEM account

edit

Identifies the SYSTEM account using the Net utility. The Net utility is a component of the Windows operating system. It is used in command line operations for control of users, groups, services, and network connections.

Rule type: query

Rule indices:

  • winlogbeat-*

Severity: low

Risk score: 21

Runs every: 5 minutes

Searches indices from: now-6m (Date Math format, see also Additional look-back time)

Maximum signals per execution: 100

Tags:

  • Elastic
  • Windows

Version: 1

Added (Elastic Stack release): 7.7.0

Rule query

edit
(process.name:net.exe or process.name:net1.exe and not
process.parent.name:net.exe) and user.name:SYSTEM and
event.action:"Process Create (rule: ProcessCreate)"

Threat mapping

edit

Framework: MITRE ATT&CKTM