Account Manipulation via net.exe Adding Users to Admin Groups (T1098)
Detects the use of the Windows net.exe or net1.exe utilities to add users to privileged groups such as 'Administrators' or 'Domain Admins'. This is a common technique used by attackers to achieve privilege escalation or establish persistence by modifying sensitive account group memberships.
SentinelOne

