ENUM4LINUX
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Enum4linux-ng is a tool for enumerating Windows/Samba systems. Extracts user lists, shares, groups, and policy information.
INSTALLATION#
# Clone enum4linux-ng (modern Python version) git clone https://github.com/cddmp/enum4linux-ng cd enum4linux-ng pip install -r requirements.txt # Or pip pip install enum4linux-ng
BASIC USAGE#
FULL ENUMERATION#
# All enumeration (default) enum4linux-ng TARGET # With credentials enum4linux-ng -u user -p 'password' TARGET enum4linux-ng -u user -p 'password' -d DOMAIN TARGET # Null session enum4linux-ng -u '' -p '' TARGET
SPECIFIC CHECKS#
# Users enumeration enum4linux-ng -U TARGET # Shares enumeration enum4linux-ng -S TARGET # Groups enumeration enum4linux-ng -G TARGET # Password policy enum4linux-ng -P TARGET # OS information enum4linux-ng -O TARGET # All (comprehensive) enum4linux-ng -A TARGET
OPTIONS#
AUTHENTICATION#
-u USERNAME Username -p PASSWORD Password -d DOMAIN Domain name -w WORKGROUP Workgroup
ENUMERATION MODULES#
-U User enumeration via RID cycling -G Group enumeration -S Share enumeration -P Password policy -O OS information -A All enumeration -M Machine enumeration -R RID range (default: 500-550,1000-1050)
OUTPUT#
-oJ FILE JSON output -oY FILE YAML output -oA FILE All formats (JSON + YAML) -v Verbose
OTHER#
-t TIMEOUT Timeout for RPC --shares Enumerate shares via RPC --users Enumerate users via RPC
ENUMERATION TECHNIQUES#
USER ENUMERATION#
# Via RID cycling enum4linux-ng -U TARGET # Custom RID range enum4linux-ng -U -R 500-2000 TARGET # Via SAMR enum4linux-ng --users TARGET
GROUP ENUMERATION#
# Local groups enum4linux-ng -G TARGET # Domain groups (with creds) enum4linux-ng -G -u user -p pass TARGET
SHARE ENUMERATION#
# List shares enum4linux-ng -S TARGET # Check access enum4linux-ng -S --shares TARGET
PASSWORD POLICY#
# Get policy enum4linux-ng -P TARGET # Useful for: # - Password complexity # - Lockout threshold # - Password age
LEGACY ENUM4LINUX#
# Original Perl version (if needed) enum4linux TARGET # Options similar but different syntax enum4linux -a TARGET # All enum4linux -U TARGET # Users enum4linux -S TARGET # Shares enum4linux -G TARGET # Groups enum4linux -P TARGET # Password policy enum4linux -o TARGET # OS info enum4linux -n TARGET # Nmblookup enum4linux -r TARGET # RID cycling
OUTPUT INTERPRETATION#
USERS#
# Look for: # - Service accounts (svc_*) # - Admin accounts # - Interesting descriptions # - Disabled accounts
GROUPS#
# Important groups: # - Domain Admins # - Enterprise Admins # - Administrators # - Remote Desktop Users # - Backup Operators
SHARES#
# Look for: # - Writable shares # - Uncommon shares # - Home directories # - Backup shares
PASSWORD POLICY#
# Important values: # - Minimum password length # - Password complexity # - Account lockout threshold # - Lockout duration
COMMON WORKFLOWS#
INITIAL FOOTHOLD#
# 1. Quick enumeration enum4linux-ng -A TARGET # 2. Get users for spraying enum4linux-ng -U TARGET | grep "user:" | cut -d: -f2 > users.txt # 3. Get password policy enum4linux-ng -P TARGET # 4. Password spray # (respecting lockout policy)
WITH CREDENTIALS#
# More complete enumeration enum4linux-ng -A -u user -p 'password' -d DOMAIN TARGET # Save output enum4linux-ng -A -u user -p pass TARGET -oA results
AUTOMATED ANALYSIS#
# JSON output for parsing enum4linux-ng -A TARGET -oJ output.json # Parse users cat output.json | jq '.users' # Parse shares cat output.json | jq '.shares'
INTEGRATION#
WITH CRACKMAPEXEC#
# Quick share check nxc smb TARGET --shares # User enumeration nxc smb TARGET --users --rid-brute
WITH RPCCLIENT#
# Interactive rpcclient -U user%pass TARGET > enumdomusers > enumdomgroups > queryuser 500
WITH SMBCLIENT#
# List shares smbclient -L //TARGET -U user%pass # Connect to share smbclient //TARGET/share -U user%pass
WITH LDAPSEARCH#
# LDAP enumeration ldapsearch -x -H ldap://TARGET -D "user@domain" -w 'pass' -b "DC=domain,DC=local"
TROUBLESHOOTING#
# SMB version issues enum4linux-ng --smb-version 2 TARGET # Timeout issues enum4linux-ng -t 60 TARGET # Anonymous access denied # Try guest account enum4linux-ng -u 'guest' -p '' TARGET # RID cycling blocked # Use LDAP enumeration instead
QUICK REFERENCE#
enum4linux-ng TARGET # Basic enumeration enum4linux-ng -A TARGET # All checks enum4linux-ng -U TARGET # Users enum4linux-ng -S TARGET # Shares enum4linux-ng -G TARGET # Groups enum4linux-ng -P TARGET # Password policy enum4linux-ng -u user -p pass TARGET # With credentials enum4linux-ng -oJ output.json TARGET # JSON output