githubEdit

user-enum-with-access

Crackmapexec

sudo nxc smb <ip> -u htb-student -p Academy_student_AD! --users

Windapsearch

Domain admin enumeration

Impacket-windapsearch --dc-ip 172.16.5.5 -u forend@inalnefreight.lcoal -p klmcargo2 --da

Privileged user enumeration

Impacket-windapsearch --dc-ip 172.16.5.5 -u forend@inalnefreight.lcoal -p klmcargo2 -PU

Linux credentials enumeration (after acquired foothold in the domain)

Netexec

  • Domain user enumeration

sudo nxc smb 172.16.5.5 -u forend -p klmcargo3 --users
  • Domain group enumeration

sudo nxc smb 172.16.5.5 -u forend -p klmcargo3 --groups
  • Logged on users

  • Search share (DC)

  • Search information inside share

Smbmap

  • Access check

  • List all directories (recursive)

rpcclient

  • SMB Null session check

Last updated