👤Enumerating Users
Enumeration Without Credentials
NSrpcenum
NSrpcenum -e DUsers -i 10.10.10.10rpcclient (No Credentials)
for i in $(seq 1000 1500); do rpcclient -N -U "" 10.10.10.10 -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name"; done | awk '{print $NF}'Kerbrute Username Enumeration
# Brute force users through Kerberos with a dictionary
kerbrute userenum --dc 10.10.10.10 -d domain.htb /usr/share/seclists/Usernames/xato-net-10-million-usernames.txt
# Validate if users are valid at domain level with a list of possible users
kerbrute userenum --dc 10.10.10.10 -d domain.htb possible_users.txtNetExec with Guest User
NetExec Kerberos Enumeration Brute Force
ridenum
impacket-lookupsid (No Credentials)
Enumeration With Credentials
ldapdomaindump
rpcenum (Modified)
rpcclient (With Credentials)
NetExec (With Credentials)
impacket-lookupsid (With Credentials)
ldapsearch
Last updated