net1.exe
Summary
Net1.exe is the worker process that performs the actual operations for net.exe commands. When net.exe is called, it spawns net1.exe with the same arguments to do the work. Net1.exe can also be called directly, bypassing net.exe.
net1.exe is the 63rd most commonly executed Windows program in EchoTrail's dataset, observed 497,761 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by LTSVC.exe.
Behavior
Top Paths
- C:\Windows\System3298.58%
- C:\Windows\SysWOW641.42%
Top Hashes (SHA256)
- 325158c8f4b250fe7438c88c8bac47aedebece852aac5926308ca7dc29d7e31c37.01%
- d28bc8fa6e80316833c0ebb948b46511971b96635892f40998a216a2dd5ec8aa10.19%
- 253e6148ec7a95ea3950e032f9def1ec7c0e0cd172cc6d770d2807a64fc4a7ca9.6%
- c687157fd58eaa51757cda87d06c30953a31f03f5356b9f5a9c004fa4bad4bf59.31%
- 286e7f127b06386bd1cc9664851848f483a867f0f604aa352893151068715faa7.19%
- fa6c66ef1379e143a2dafd5b458796cbfe464ec88279a9bf34b085019e6bbf106.67%
- f4cbb5284b2d0334a1f65060cbfff1e382ca7a0c35e6bd4031710f301ff9816b5.85%
- 195a557e92a631e29ecf789c360a99c0f5d2d1becea33153cca60e63d04cee014.25%
- ffc30745be3b6c2771fc4b2993cff50b5226b271c412467e97b1dc1086dea8881.98%
- 3d6de98341375c89660438934ebde5fd358030e9abc0b929c1bdf8d182fe7bff1.96%
Process Ancestry
Top Grandparents
- services.exe74.59%
- LTSVC.exe7.15%
- cmd.exe6.19%
- svchost.exe5.52%
- labvnc.exe2.82%
- Update.exe0.9%
- wgsslvpnsrc.exe0.24%
- QualysAgent.exe0.23%
- msiexec.exe0.2%
Top Parents
- LTSVC.exe56.61%
- net.exe42.83%
- Update.exe0.54%
- svchost.exe<0.01%
- WerFault.exe<0.01%
- swi_filter.exe<0.01%
- ALsvc.exe<0.01%
- Health.exe<0.01%
- OfficeClickToRun.exe<0.01%
- SAVAdminService.exe<0.01%
Top Children
- conhost.exe100%
- find.exe<0.01%
- sc.exe<0.01%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Security Analysis
What does net1.exe normally do?
Located in C:\Windows\System32 or C:\Windows\SysWOW64. Launched by net.exe (most common) or directly by management agents (LTSVC.exe). Spawns conhost.exe.
When is net1.exe suspicious?
Same as net.exe — the command-line arguments reveal the intent. Launched directly (not by net.exe) — while legitimate, this can be an evasion technique to avoid net.exe-based detections. Same discovery/manipulation patterns as net.exe.
How do attackers abuse net1.exe?
Identical to net.exe. Attackers may call net1.exe directly to evade detections that only monitor net.exe. The command-line arguments are the same.
Detection guidance
Apply the same detection logic as net.exe to net1.exe. Detections that only monitor net.exe and miss net1.exe have a blind spot. Monitor both process names with the same command-line rules.
False positive notes
Same as net.exe. Heavy management agent usage.
Related Processes
Ask Rocky about net1.exe
Rocky answers questions about net1.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.