Active Directory Enumeration via Net Commands on DC

This rule detects the execution of common enumeration commands (net, dsquery) on systems identified as Domain Controllers. These commands are frequently used by adversaries for reconnaissance to identify local or domain users and groups after gaining access to a host.