net1.exe

by Microsoft
Operating Systemhigh risk

Sources: 300M+ executions observed in the wild.

Summary

Net1.exe is the worker process that performs the actual operations for net.exe commands. When net.exe is called, it spawns net1.exe with the same arguments to do the work. Net1.exe can also be called directly, bypassing net.exe.

net1.exe is the 63rd most commonly executed Windows program in EchoTrail's dataset, observed 497,761 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.

Get this in your tools

The same record for net1.exe, by REST or as an MCP tool. Free key, no card.

Get a free key
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
  https://api.echotrail.io/v1/process/net1.exe

Free returns the summary. Team returns the full record you see on this page. Endpoint docs

63rd
most commonly executed Windows program
497,761
observed endpoint executions

Behavior

Top Paths

  • C:\Windows\System3298.58%
  • C:\Windows\SysWOW641.42%

Top Hashes (SHA256)

  • 325158c8f4b250fe7438c88c8bac47aedebece852aac5926308ca7dc29d7e31c37.01%
  • d28bc8fa6e80316833c0ebb948b46511971b96635892f40998a216a2dd5ec8aa10.19%
  • 253e6148ec7a95ea3950e032f9def1ec7c0e0cd172cc6d770d2807a64fc4a7ca9.6%
  • c687157fd58eaa51757cda87d06c30953a31f03f5356b9f5a9c004fa4bad4bf59.31%
  • 286e7f127b06386bd1cc9664851848f483a867f0f604aa352893151068715faa7.19%
  • fa6c66ef1379e143a2dafd5b458796cbfe464ec88279a9bf34b085019e6bbf106.67%
  • f4cbb5284b2d0334a1f65060cbfff1e382ca7a0c35e6bd4031710f301ff9816b5.85%
  • 195a557e92a631e29ecf789c360a99c0f5d2d1becea33153cca60e63d04cee014.25%
  • ffc30745be3b6c2771fc4b2993cff50b5226b271c412467e97b1dc1086dea8881.98%
  • 3d6de98341375c89660438934ebde5fd358030e9abc0b929c1bdf8d182fe7bff1.96%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Security Analysis

What does net1.exe normally do?

Located in C:\Windows\System32 or C:\Windows\SysWOW64. Launched by net.exe (most common) or directly by management agents (LTSVC.exe). Spawns conhost.exe.

When is net1.exe suspicious?

Same as net.exe — the command-line arguments reveal the intent. Launched directly (not by net.exe) — while legitimate, this can be an evasion technique to avoid net.exe-based detections. Same discovery/manipulation patterns as net.exe.

How do attackers abuse net1.exe?

Identical to net.exe. Attackers may call net1.exe directly to evade detections that only monitor net.exe. The command-line arguments are the same.

Detection guidance

Apply the same detection logic as net.exe to net1.exe. Detections that only monitor net.exe and miss net1.exe have a blind spot. Monitor both process names with the same command-line rules.

False positive notes

Same as net.exe. Heavy management agent usage.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about net1.exe

Rocky is the free chat demo. It answers from this same dataset, no account needed.

This page is the Team-tier API record for net1.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.