We recently improved the coverage of the "Reconnaissance via Net Commands" detection so that it detects more activity. A portion of the detection logic previously looked only for net.exe and it now includes net1.exe in the logic.
You may find that you are receiving new findings for expected software activity even though changes have not been made to that software. If the activity is expected and you do not want to receive findings, you can use a detection filter to tune out the noise.
Reference: See these articles for steps and best practice recommendations: