Local and Domain Account Enumeration via net.exe (T1087.001)

Detects the execution of net.exe or net1.exe with command line arguments used to enumerate domain users, domain groups, or local administrators. This pattern is commonly used by adversaries for discovery of accounts and permission groups within a Windows environment.