Gathering Users & Password Policies
Gathering Users
User Enumeration Techniques for Active Directory Attacks
enum4linux -U {DC-IP}
rpcclient -U "" -N {DC-IP}rpcclient$> enumdomusers
crackmapexec smb {DC-IP} --users
ldapsearch -h {DC-IP} -x -b "DC=MARVEL,DC=LOCAL" -s sub "(&(objectclass=user))"
./windapsearch.py --dc-ip {DC-IP} -u "" -U
kerbrute userenum -d marvel.local --dc {DC-IP} /opt/seclists/usernames/xato-net-10-million-usernames.txt
crackmapexec smb {DC-IP} -u 'guest' -p '' --rid-brute
Enumerating Password Policies
Enumerating & Retrieving Password Policies - Credentialed ⭐
Enumerating Password Policies - SMB NULL Sessions ⭐
Enumerating Null Sessions - from Windows
Enumerating Password Policies - LDAP Anonymous Bind
Last updated