Can your SOC see someone asking where this box is already connected?
One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.
technique T1049 · System Network Connections Discoveryseen in Volt Typhoonwhere any Windows box
What this is about
Can your SOC see an attacker listing the live connections?
A machine's live connections are a shortcut. Every one of them is a place this account has already been trusted, which means the intruder does not have to guess where to go next — the box will tell them. net use prints them.
The detection watches for that specific use of net: not the form that mounts something new, the form that reads back what is already there. Your admins run it too, which is why the rule is about the behaviour and the context around it rather than the tool.
The detection watches one thing: the built-in net command being used to list the connections this machine already holds.
This is not hypothetical
The intrusion set tracked as Volt Typhoon is documented enumerating network connections on the systems it reaches. The whole tradecraft in that case is built on not bringing tools: live off what the machine already has, read what it already knows, and keep the footprint small enough that nothing looks like malware.
This is the step where that pays off — one built-in command, no rights required, and the map of trusted destinations arrives for free.
The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.
A live connection is a destination this account is already trusted on. Reading the list saves an attacker the guessing, and the noise that guessing makes.
It comes before lateral movement
Connection discovery is reconnaissance for the next hop. Catch it and you are ahead of the movement, not cleaning up after it.
Built in and unelevated
net ships with Windows and needs no admin to list what is already connected. There is no binary to block, so the behaviour has to be watched.
The test
Run the real thing. Safely. On a box you own.
Run the same connection listing an intruder runs, then open your alerts.
01
List what this machine already reaches
Run net use with no arguments — the built-in that prints the connections this account currently holds. This is the moment your SOC should notice.
02
Read it as an attacker would
Every entry is somewhere this account is already accepted. That list is the shortlist for the next hop.
03
Check your alerts
Open your SOC or EDR. Did network connection discovery fire — or did the shortlist get read in silence?
test-your-soc-network-connections.ps1 · PowerShell · a machine you own
# test-your-soc-network-connections.ps1 — run on a machine you own.
# Safe: read-only. Lists connections that already exist; creates none. Nothing to undo.
# STEP 1 - list the connections this machine already holds.
net use
# STEP 2 - open your SOC / EDR. Did network connection discovery alert?
net use with no arguments only prints the connections that already exist — it creates, mounts and removes nothing. There is nothing to undo and no admin rights are needed. If the list comes back empty, the test is still valid: the detection watches the command running, not what it prints.
Reading the result — honestly
Something fired
Your tooling watches for connection enumeration
Good — you would see an intruder reading the shortlist before they used it. On to the next one.
Silence
The enumeration went unseen — now you know
Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below closes it.
Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged net use — note that the same question can be asked with netstat or from PowerShell, which this rule does not cover, so treat it as one door of several. Treat a pass as a reason to go check prod, not a finish line.
How to catch it
Missed it? Here’s the fix — take it straight to your SOC.
Copy this to your detection team
The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.
title: System Network Connections Discovery Via Net.EXEid: 1c67a717-32ba-409b-a45d-0fb704a73a81status: testdescription: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.references: - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1049/T1049.md#atomic-test-1---system-network-connections-discoveryauthor: frack113date: 2021-12-10modified: 2023-02-21tags: - attack.discovery
- attack.t1049
logsource: category: process_creation product: windowsdetection: selection_img: - Image|endswith: - '\net.exe'
- '\net1.exe'
- OriginalFileName: - 'net.exe'
- 'net1.exe'
selection_cli: - CommandLine|endswith: - ' use'
- ' sessions'
- CommandLine|contains: - ' use '
- ' sessions '
condition: all of selection_*falsepositives: - Unknown
level: low
System Network Connections Discovery Via Net.EXE · SigmaHQ rule 1c67a717-32ba-409b-a45d-0fb704a73a81
If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.
A new one every week
This is technique 07 of many.
Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.
Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →
Credit & sources
The technique and the incident are documented by MITRE ATT&CK (T1049) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.
We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI