A simple query to look for executions of net.exe that make use of the account switch. These are sometimes used by adversaries to discover the local and domain password policies that are in enforced.
-- Account Discovery: Password Policies -- T1201 looking...