Discovery using nltest, net and whoami

Quick, high-signal ways to enumerate DCs, trusts, and privileged groups in Active Directory plus how to detect them.

Overview

  • Why it matters: these commands are common during early recon.
  • What you get: exact commands, sample output, Sigma detections, and in-the-wild cases.
  • Defend: pair command-line telemetry with parent/child process context and alert tuning.

Known in-the-wild incidents

Source Title Source (with link) Publish Date Commands referred
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs The DFIR Report 8 Sep, 2025 nltest for AD/DC enumeration
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira The DFIR Report 5 Aug, 2025 nltest /dclist:; nltest /domain_trusts; whoami /groups; net group "domain admins" /dom; net group "enterprise admins" /dom
SharePoint ToolShell – Zero-Day Exploited in-the-Wild Targets Enterprise Servers SentinelLabs 21 Jul, 2025 whoami (captured via webshell command execution)
#StopRansomware: Play Ransomware CISA 4 Jun, 2025 nltest used for network discovery (behavior described, exact switches not quoted)
QSC: new modular framework in CloudComputating campaigns Securelist 8 Nov, 2024 net group "domain admins" /domain; whoami
Attack Cases Against HTTP File Server (HFS) (CVE-2024-23692) AhnLab ASEC 28 Jun, 2024 whoami during post-exploitation reconnaissance
Operation Crimson Palace: A Technical Deep Dive Sophos X-Ops 5 Jun, 2024 net group "domain admins" /domain; nltest /domain_trusts (plus related domain enumeration)

Sigma Rules

Visual mapping

Command-to-rule mapping for nltest, whoami, and net.

Elastic Sigma alerts

Potential Recon Activity Via Nltest.EXE

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.

nltest.exe /dclist: domain
nltest.exe /domain_trusts

Example output

C:\Users\john>nltest /dclist:DC1
Get list of DCs in domain 'DC1' from '\\HOME-DC'.
    HOME-DC.DC1.local [PDC]  [DS] Site: Default-First-Site-Name
The command completed successfully

C:\Users\john>nltest /domain_trusts
List of domain trusts:
    0: DC1 DC1.local (NT 5) (Forest Tree Root) (Primary Domain) (Native)
The command completed successfully

Suspicious Group And Account Reconnaissance Activity Using Net.EXE

net.exe group "domain admins" /dom
net.exe group "enterprise admins" /dom

Example output

  1. net group "domain admins" /dom
C:\Users\john>net group "domain admins" /dom
The request will be processed at a domain controller for domain DC1.local.

Group name     Domain Admins
Comment        Designated administrators of the domain

Members

-------------------------------------------------------------------------------
Administrator            MSSQLService             user2
The command completed successfully.
  1. net group "enterprise admins" /dom
C:\Users\john>net group "enterprise admins" /dom
The request will be processed at a domain controller for domain DC1.local.

Group name     Enterprise Admins
Comment        Designated administrators of the enterprise

Members

-------------------------------------------------------------------------------
Administrator            MSSQLService             user1
The command completed successfully.

Group Membership Reconnaissance Via Whoami.EXE

whoami.exe /groups

Example output

C:\Users\john>whoami /groups

GROUP INFORMATION
-----------------

Group Name                                 Type             SID          Attributes
========================================== ================ ============ ==================================================
Everyone                                   Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Administrators                     Alias            S-1-5-32-544 Group used for deny only
BUILTIN\Users                              Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE                   Well-known group S-1-5-4      Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON                              Well-known group S-1-2-1      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users           Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
....

SIEM Detections

These queries were generated by converting the Sigma rule with pySigma backends.

Potential Recon Activity Via Nltest.EXE

Detects nltest commands that can be used for information discovery

DeviceProcessEvents
| where (FolderPath endswith "\\nltest.exe" or ProcessVersionInfoOriginalFileName =~ "nltestrk.exe") and ((ProcessCommandLine contains "server" and ProcessCommandLine contains "query") or (ProcessCommandLine contains "/user" or ProcessCommandLine contains "all_trusts" or ProcessCommandLine contains "dclist:" or ProcessCommandLine contains "dnsgetdc:" or ProcessCommandLine contains "domain_trusts" or ProcessCommandLine contains "dsgetdc:" or ProcessCommandLine contains "parentdomain" or ProcessCommandLine contains "trusted_domains"))
(process.executable:*\\nltest.exe OR process.pe.original_file_name:nltestrk.exe) AND ((process.command_line:*server* AND process.command_line:*query*) OR (process.command_line:(*\/user* OR *all_trusts* OR *dclist\:* OR *dnsgetdc\:* OR *domain_trusts* OR *dsgetdc\:* OR *parentdomain* OR *trusted_domains*)))

Suspicious Group And Account Reconnaissance Activity Using Net.EXE

Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)

DeviceProcessEvents
| where ((FolderPath endswith "\\net.exe" or FolderPath endswith "\\net1.exe") or (ProcessVersionInfoOriginalFileName in~ ("net.exe", "net1.exe"))) and ((((ProcessCommandLine contains " group " or ProcessCommandLine contains " localgroup ") and (ProcessCommandLine contains "domain admins" or ProcessCommandLine contains " administrator" or ProcessCommandLine contains " administrateur" or ProcessCommandLine contains "enterprise admins" or ProcessCommandLine contains "Exchange Trusted Subsystem" or ProcessCommandLine contains "Remote Desktop Users" or ProcessCommandLine contains "Utilisateurs du Bureau à distance" or ProcessCommandLine contains "Usuarios de escritorio remoto" or ProcessCommandLine contains " /do")) and (not(ProcessCommandLine contains " /add"))) or (ProcessCommandLine contains " accounts " and ProcessCommandLine contains " /do"))
((process.executable:(*\\net.exe OR *\\net1.exe)) OR (process.pe.original_file_name:(net.exe OR net1.exe))) AND ((((process.command_line:(*\ group\ * OR *\ localgroup\ *)) AND (process.command_line:(*domain\ admins* OR *\ administrator* OR *\ administrateur* OR *enterprise\ admins* OR *Exchange\ Trusted\ Subsystem* OR *Remote\ Desktop\ Users* OR *Utilisateurs\ du\ Bureau\ à\ distance* OR *Usuarios\ de\ escritorio\ remoto* OR *\ \/do*))) AND (NOT process.command_line:*\ \/add*)) OR (process.command_line:*\ accounts\ * AND process.command_line:*\ \/do*))

Group Membership Reconnaissance Via Whoami.EXE

Detects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.

DeviceProcessEvents
| where (FolderPath endswith "\\whoami.exe" or ProcessVersionInfoOriginalFileName =~ "whoami.exe") and (ProcessCommandLine contains " /groups" or ProcessCommandLine contains " -groups")
(process.executable:*\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND (process.command_line:(*\ \/groups* OR *\ \-groups*))

Thanks to @svch0st, Craig Young, @cyb3rops, Georg Lauenstein, @nas_bench, omkar72, and oscd.community for publishing the awesome Sigma rules and helping the community.

References

Thanks for reading. Feel free to connect with me on or LinkedIn for any suggestions or comments.

For more updates and exclusive content, subscribe to our newsletter. Stay sharp. Keep defending.😊

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

keyboard_arrow_up