user-enum-without-access
enum4linux -U 172.16.5.5 | grep "user:" | cut -f2 -d"[" | cut -f1 -d"]" OR enum4linux-ng -P "$ip" -oA "$out"rpcclient -U "" -N 172.16.5.5 -c "enumdomusers; querydominfo; exit"for i in $(seq 500 50000);do rpcclient -N -U "" 10.129.14.128 -c "queryuser 0x$(printf '%x\n' $i)"|grep "User Name\|user_rid\|group_rid" && echo "";done OR ridenum 192.168.1.236 500 50000kerbrute userenum /opt/SecLists/Usernames/cirt-default-usernames.txt --dc dc01.manager.htb -d manager.htbnxc smb 172.16.5.5 --usersnxc smb 172.16.5.5 -u user -p password --usersimpacket-lookupsid -no-pass domain.localldapsearch -h 172.16.5.5 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "(&(objectclass=user))" | grep sAMAccountName: | cut -f2 -d" "Last updated