← All cheat sheets

ENUM4LINUX

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Enum4linux-ng is a tool for enumerating Windows/Samba systems.
Extracts user lists, shares, groups, and policy information.

INSTALLATION#

# Clone enum4linux-ng (modern Python version)
git clone https://github.com/cddmp/enum4linux-ng
cd enum4linux-ng
pip install -r requirements.txt

# Or pip
pip install enum4linux-ng

BASIC USAGE#


    

FULL ENUMERATION#

# All enumeration (default)
enum4linux-ng TARGET

# With credentials
enum4linux-ng -u user -p 'password' TARGET
enum4linux-ng -u user -p 'password' -d DOMAIN TARGET

# Null session
enum4linux-ng -u '' -p '' TARGET

SPECIFIC CHECKS#

# Users enumeration
enum4linux-ng -U TARGET

# Shares enumeration
enum4linux-ng -S TARGET

# Groups enumeration
enum4linux-ng -G TARGET

# Password policy
enum4linux-ng -P TARGET

# OS information
enum4linux-ng -O TARGET

# All (comprehensive)
enum4linux-ng -A TARGET

OPTIONS#


    

AUTHENTICATION#

-u USERNAME     Username
-p PASSWORD     Password
-d DOMAIN       Domain name
-w WORKGROUP    Workgroup

ENUMERATION MODULES#

-U              User enumeration via RID cycling
-G              Group enumeration
-S              Share enumeration
-P              Password policy
-O              OS information
-A              All enumeration
-M              Machine enumeration
-R              RID range (default: 500-550,1000-1050)

OUTPUT#

-oJ FILE        JSON output
-oY FILE        YAML output
-oA FILE        All formats (JSON + YAML)
-v              Verbose

OTHER#

-t TIMEOUT      Timeout for RPC
--shares        Enumerate shares via RPC
--users         Enumerate users via RPC

ENUMERATION TECHNIQUES#


    

USER ENUMERATION#

# Via RID cycling
enum4linux-ng -U TARGET

# Custom RID range
enum4linux-ng -U -R 500-2000 TARGET

# Via SAMR
enum4linux-ng --users TARGET

GROUP ENUMERATION#

# Local groups
enum4linux-ng -G TARGET

# Domain groups (with creds)
enum4linux-ng -G -u user -p pass TARGET

SHARE ENUMERATION#

# List shares
enum4linux-ng -S TARGET

# Check access
enum4linux-ng -S --shares TARGET

PASSWORD POLICY#

# Get policy
enum4linux-ng -P TARGET

# Useful for:
# - Password complexity
# - Lockout threshold
# - Password age

LEGACY ENUM4LINUX#

# Original Perl version (if needed)
enum4linux TARGET

# Options similar but different syntax
enum4linux -a TARGET           # All
enum4linux -U TARGET           # Users
enum4linux -S TARGET           # Shares
enum4linux -G TARGET           # Groups
enum4linux -P TARGET           # Password policy
enum4linux -o TARGET           # OS info
enum4linux -n TARGET           # Nmblookup
enum4linux -r TARGET           # RID cycling

OUTPUT INTERPRETATION#


    

USERS#

# Look for:
# - Service accounts (svc_*)
# - Admin accounts
# - Interesting descriptions
# - Disabled accounts

GROUPS#

# Important groups:
# - Domain Admins
# - Enterprise Admins
# - Administrators
# - Remote Desktop Users
# - Backup Operators

SHARES#

# Look for:
# - Writable shares
# - Uncommon shares
# - Home directories
# - Backup shares

PASSWORD POLICY#

# Important values:
# - Minimum password length
# - Password complexity
# - Account lockout threshold
# - Lockout duration

COMMON WORKFLOWS#


    

INITIAL FOOTHOLD#

# 1. Quick enumeration
enum4linux-ng -A TARGET

# 2. Get users for spraying
enum4linux-ng -U TARGET | grep "user:" | cut -d: -f2 > users.txt

# 3. Get password policy
enum4linux-ng -P TARGET

# 4. Password spray
# (respecting lockout policy)

WITH CREDENTIALS#

# More complete enumeration
enum4linux-ng -A -u user -p 'password' -d DOMAIN TARGET

# Save output
enum4linux-ng -A -u user -p pass TARGET -oA results

AUTOMATED ANALYSIS#

# JSON output for parsing
enum4linux-ng -A TARGET -oJ output.json

# Parse users
cat output.json | jq '.users'

# Parse shares
cat output.json | jq '.shares'

INTEGRATION#


    

WITH CRACKMAPEXEC#

# Quick share check
nxc smb TARGET --shares

# User enumeration
nxc smb TARGET --users --rid-brute

WITH RPCCLIENT#

# Interactive
rpcclient -U user%pass TARGET
> enumdomusers
> enumdomgroups
> queryuser 500

WITH SMBCLIENT#

# List shares
smbclient -L //TARGET -U user%pass

# Connect to share
smbclient //TARGET/share -U user%pass

WITH LDAPSEARCH#

# LDAP enumeration
ldapsearch -x -H ldap://TARGET -D "user@domain" -w 'pass' -b "DC=domain,DC=local"

TROUBLESHOOTING#

# SMB version issues
enum4linux-ng --smb-version 2 TARGET

# Timeout issues
enum4linux-ng -t 60 TARGET

# Anonymous access denied
# Try guest account
enum4linux-ng -u 'guest' -p '' TARGET

# RID cycling blocked
# Use LDAP enumeration instead

QUICK REFERENCE#

enum4linux-ng TARGET                    # Basic enumeration
enum4linux-ng -A TARGET                 # All checks
enum4linux-ng -U TARGET                 # Users
enum4linux-ng -S TARGET                 # Shares
enum4linux-ng -G TARGET                 # Groups
enum4linux-ng -P TARGET                 # Password policy
enum4linux-ng -u user -p pass TARGET    # With credentials
enum4linux-ng -oJ output.json TARGET    # JSON output