net1.exe

by Microsoft
Operating Systemhigh risk

Summary

Net1.exe is the worker process that performs the actual operations for net.exe commands. When net.exe is called, it spawns net1.exe with the same arguments to do the work. Net1.exe can also be called directly, bypassing net.exe.

net1.exe is the 63rd most commonly executed Windows program in EchoTrail's dataset, observed 497,761 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.

63rd
most commonly executed Windows program
497,761
observed executions
medium
statistical confidence

Behavior

Top Paths

  • C:\Windows\System3298.58%
  • C:\Windows\SysWOW641.42%

Top Hashes (SHA256)

  • 325158c8f4b250fe7438c88c8bac47aedebece852aac5926308ca7dc29d7e31c37.01%
  • d28bc8fa6e80316833c0ebb948b46511971b96635892f40998a216a2dd5ec8aa10.19%
  • 253e6148ec7a95ea3950e032f9def1ec7c0e0cd172cc6d770d2807a64fc4a7ca9.6%
  • c687157fd58eaa51757cda87d06c30953a31f03f5356b9f5a9c004fa4bad4bf59.31%
  • 286e7f127b06386bd1cc9664851848f483a867f0f604aa352893151068715faa7.19%
  • fa6c66ef1379e143a2dafd5b458796cbfe464ec88279a9bf34b085019e6bbf106.67%
  • f4cbb5284b2d0334a1f65060cbfff1e382ca7a0c35e6bd4031710f301ff9816b5.85%
  • 195a557e92a631e29ecf789c360a99c0f5d2d1becea33153cca60e63d04cee014.25%
  • ffc30745be3b6c2771fc4b2993cff50b5226b271c412467e97b1dc1086dea8881.98%
  • 3d6de98341375c89660438934ebde5fd358030e9abc0b929c1bdf8d182fe7bff1.96%

Process Ancestry

Top Grandparents

Top Parents

Top Children

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does net1.exe normally do?

Located in C:\Windows\System32 or C:\Windows\SysWOW64. Launched by net.exe (most common) or directly by management agents (LTSVC.exe). Spawns conhost.exe.

When is net1.exe suspicious?

Same as net.exe — the command-line arguments reveal the intent. Launched directly (not by net.exe) — while legitimate, this can be an evasion technique to avoid net.exe-based detections. Same discovery/manipulation patterns as net.exe.

How do attackers abuse net1.exe?

Identical to net.exe. Attackers may call net1.exe directly to evade detections that only monitor net.exe. The command-line arguments are the same.

Detection guidance

Apply the same detection logic as net.exe to net1.exe. Detections that only monitor net.exe and miss net1.exe have a blind spot. Monitor both process names with the same command-line rules.

False positive notes

Same as net.exe. Heavy management agent usage.

MITRE ATT&CK techniques

Related Processes

Ask Rocky about net1.exe

Rocky answers questions about net1.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.