Active Directory
Active Directory Tools and Stuff
smbclient
smbmap -H 10.129.148.199
smbclient -N -L //10.129.148.199
smbmap -H 10.10.10.52 -u james -p 'J@m3s_P@ssW0rd!'rpcclient
rpcclient -U '' -N 10.129.148.19 # -N for no password -U for username$ rpcclient -U htb.local/james 10.129.148.199
Enter HTB.LOCAL\james's password:
rpcclient $> enumdom
enumdomains enumdomgroups enumdomusers
rpcclient $> enumdom
enumdomains enumdomgroups enumdomusers
rpcclient $> enumdomusers
user:[Administrator] rid:[0x1f4]
user:[Guest] rid:[0x1f5]
user:[krbtgt] rid:[0x1f6]
user:[james] rid:[0x44f]
rpcclient $>Kerbrute
Impacket-Tools
Crackmapexec
Last updated