This is not hypothetical
The Conti ransomware operation is documented running exactly this on the way in. Their own leaked playbooks walk operators through net view and share enumeration as a first step, because the shares are where the data — and the next set of credentials — live.
It is a command that ships with Windows, run by an ordinary account. The same line you are about to run — the only question is whether your SOC notices the network being counted.
The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.