Domain Group Enumeration via net.exe group /domain (T1069.002)
Detects the use of the 'net.exe' or 'net1.exe' utilities with the 'group' and '/domain' arguments, indicating an attempt to query domain-level groups. This technique is commonly used by attackers during the discovery phase to map out domain security groups.
SentinelOne

