Test your SOC · about a minute

Can your SOC see someone counting the doors?

One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.

technique T1018 · Remote System Discoveryseen in Contiwhere any Windows box

What this is about

Can your SOC see an attacker mapping the network?

Once an intruder has a foothold, the next question is: what else can I reach? net view answers it — a built-in command that lists the file shares, printer shares and active sessions visible from this machine. It is how a hands-on attacker builds the map they use to spread.

The detection watches for net view doing broad enumeration — not the single, targeted lookup an admin runs, but the sweep an intruder runs to find where to go next.

The detection watches one thing: the built-in net command being used to enumerate shares and sessions across the network.

This is not hypothetical

The Conti ransomware operation is documented running exactly this on the way in. Their own leaked playbooks walk operators through net view and share enumeration as a first step, because the shares are where the data — and the next set of credentials — live.

It is a command that ships with Windows, run by an ordinary account. The same line you are about to run — the only question is whether your SOC notices the network being counted.

The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.

Built-in reconnaissance

net view ships with Windows. There is no malware to catch, so the detection watches the behaviour, not a file.

It maps where to spread

Shares and sessions are the roads between machines. The enumeration is the step before lateral movement — catch it early.

No rights required

Listing visible shares needs no admin. It is quiet and it is normal-looking, which is exactly why it slips past unwatched.

The test

Run the real thing. Safely. On a box you own.

Run the same share-and-session sweep an intruder runs, then open your alerts.

01

Enumerate the neighbourhood

Run net view — the built-in that lists shares and sessions visible from this box.

02

Widen the sweep

Run net view /all — the broader enumeration an attacker uses to see everything reachable. This is the moment your SOC should speak up.

03

Check your alerts

Open your SOC or EDR. Did share-and-session enumeration fire — or did the network get mapped in silence?

test-your-soc-remote-discovery.ps1 · PowerShell · a machine you own
# test-your-soc-remote-discovery.ps1 — run on a machine you own.
# Safe: read-only enumeration. Nothing is changed, nothing to undo.
# STEP 1 - list the shares and sessions visible from this machine.
net view
# STEP 2 - the broader sweep an intruder runs to see everything reachable.
net view /all
# STEP 3 - open your SOC / EDR. Did share/session enumeration alert?

Both lines only list what is already visible on the network — nothing is created, mounted, changed or deleted. There is nothing to undo and no admin rights are needed. If the command returns an error (a modern box often answers net view with error 6118), the test is still valid — the detection watches the command running, not what it prints.

Reading the result — honestly

Something fired

Your tooling watches network enumeration

Good — you would see an intruder counting the doors before they walk through one. On to the next one.

Silence

The sweep went unseen — now you know

Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below closes it.

Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged net view enumeration — note that a targeted net view \\<one-host> is a narrower action many rules deliberately ignore, so the catch here is the broad sweep. Treat a pass as a reason to go check prod, not a finish line.

How to catch it

Missed it? Here’s the fix — take it straight to your SOC.

The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.

proc_creation_win_net_view_share_and_sessions_enum.yml
title: Share And Session Enumeration Using Net.EXE
id: 62510e69-616b-4078-b371-847da438cc03
status: stable
description: Detects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
references:
    - https://eqllib.readthedocs.io/en/latest/analytics/b8a94d2f-dc75-4630-9d73-1edc6bd26fff.html
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1018/T1018.md
author: Endgame, JHasenbusch (ported for oscd.community)
date: 2018-10-30
modified: 2023-02-21
tags:
    - attack.discovery
    - attack.t1018
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith:
              - '\net.exe'
              - '\net1.exe'
        - OriginalFileName:
              - 'net.exe'
              - 'net1.exe'
    selection_cli:
        CommandLine|contains: 'view'
    filter:
        CommandLine|contains: '\\\\'
    condition: all of selection_* and not filter
falsepositives:
    - Legitimate use of net.exe utility by legitimate user
level: low

Share And Session Enumeration Using Net.EXE · SigmaHQ rule 62510e69-616b-4078-b371-847da438cc03

Author Endgame, JHasenbusch (ported for oscd.community) · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_net_view_share_and_sessions_enum.yml

Retrieved 2026-09-11 · file sha256 46d7533fce00b99829f510a7b9f464315b6b1bf1316c951e016cf8cd54200a1f

If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.

A new one every week

This is technique 03 of many.

Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.

Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →

Credit & sources

The technique and the incident are documented by MITRE ATT&CK (T1018) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.

CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI