Impacket lookupsid

Brute-force the RID space against SAMR / LSARPC to enumerate domain users, groups, and SIDs from a low-priv account. Works against domain controllers and member servers; output is a clean SID → name mapping.

Tool
impacket-lookupsid
Category
Enumeration / SMB
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-lookupsid '<domain>/<user>:<password>@<target>'

Credential variants

The same attack using a different authentication material.

Hash Auth requires NTLM hash

impacket-lookupsid '<domain>/<user>@<target>' -hashes :<nt-hash>

Higher RID Range requires password

impacket-lookupsid '<domain>/<user>:<password>@<target>' 10000

Null Session requires no credentials

impacket-lookupsid '@<target>'

Examples

impacket-lookupsid 'corp.local/jdoe:Password123!@10.10.10.10' 4000

Tags

impacket lookupsid enumeration rid