Impacket lookupsid
Brute-force the RID space against SAMR / LSARPC to enumerate domain users, groups, and SIDs from a low-priv account. Works against domain controllers and member servers; output is a clean SID → name mapping.
- Tool
- impacket-lookupsid
- Category
- Enumeration / SMB
- Platform
- linux
- Requires
- password
- Protocols
- SMB, RPC
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
impacket-lookupsid '<domain>/<user>:<password>@<target>'
Credential variants
The same attack using a different authentication material.
Hash Auth requires NTLM hash
impacket-lookupsid '<domain>/<user>@<target>' -hashes :<nt-hash>
Higher RID Range requires password
impacket-lookupsid '<domain>/<user>:<password>@<target>' 10000
Null Session requires no credentials
impacket-lookupsid '@<target>'
Examples
impacket-lookupsid 'corp.local/jdoe:Password123!@10.10.10.10' 4000
Tags
Related commands
- Enum4linux-ng SMB Enumeration Next generation enum4linux for SMB enumeration
- Impacket NetView Enumerate logged-on users and sessions on remote hosts
- Impacket SAMRDump Dump user accounts and group information via SAMR protocol
- Impacket SMBClient Interactive SMB client written in pure Python. Drops you into a shell with shares, ls,…
- NetExec enum_ca Module Discover Active Directory Certificate Services CA hosts on the network and grab basic CA…
- NetExec MS17-010 Check (EternalBlue) Detect MS17-010 (EternalBlue) vulnerable hosts via the SMBv1 transaction probe. Safe…
- NetExec Password Policy Enumerate Domain Password Policy
- NetExec SMB Enumerate AV Enumerate installed antivirus and security products on remote hosts