Enumeration
gobuster dns -d domain.local -t 25 -w /opt/Seclist/Discovery/DNS/subdomain-top2000.txtenum4linux -a -u "" -p "" <DC IP> && enum4linux -a -u "guest" -p "" <DC IP>
smbmap -u "" -p "" -P 445 -H <DC IP> && smbmap -u "guest" -p "" -P 445 -H <DC IP>
smbclient -U '%' -L //<DC IP> && smbclient -U 'guest%' -L //
rpcclient -U "" -N <IP> #No creds
smbclient --no-pass -L //<IP> # Null usernmap -n -sV --script "ldap* and not brute" -p 389 <DC IP>ldapsearch
Last updated