RPCClient Enum Domain Users

Enumerate domain users via RPC using rpcclient

Tool
rpcclient
Category
Enumeration / SMB
Platform
linux
Requires
password
Protocols
SMB

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

rpcclient -U '<domain>/<user>%<password>' <ip> -c 'enumdomusers'

Credential variants

The same attack using a different authentication material.

Null Session requires no credentials

rpcclient -U '' -N <ip> -c 'enumdomusers'

Examples

rpcclient -U 'corp.local/user%password' 192.168.1.100 -c 'enumdomusers'
rpcclient -U '' -N 192.168.1.100 -c 'enumdomusers'

Tags

rpcclient rpc enumeration users domain