Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects the use of net.exe or net1.exe to interact with administrator accounts, specifically looking for attempts to hardcode passwords in the command line or enabling/modifying domain accounts. This is a common pattern for local account persistence, privilege escalation, or lateral movement.
avatar
Emiliano Mema@Nosalva
avatar
Detections.ai Community
2 months ago
105