Enumeration Commands
80 commands across 11 subcategories. Every entry lists the authentication material it needs, the protocols it speaks and links to upstream tool documentation.
Network Discovery 5
- Impacket DumpNTLMInfo Dump NTLM server information (OS version, domain, hostname) without credentials
- Impacket RDP Check Check if credentials are valid for RDP access
- Impacket RPCDump Enumerate RPC endpoints and interfaces registered on a remote host
- NetExec RDP NLA Screenshot Capture a pre-auth RDP login screen against hosts that have NLA enabled. Reveals OS branding, last logged-on…
- Nmap TCP Scan Comprehensive TCP port scan with service version detection and default scripts
SMB 22
- Enum4linux-ng SMB Enumeration Next generation enum4linux for SMB enumeration
- Impacket lookupsid Brute-force the RID space against SAMR / LSARPC to enumerate domain users, groups, and SIDs from a low-priv…
- Impacket NetView Enumerate logged-on users and sessions on remote hosts
- Impacket SAMRDump Dump user accounts and group information via SAMR protocol
- Impacket SMBClient Interactive SMB client written in pure Python. Drops you into a shell with shares, ls, get, put, mkdir, rm,…
- NetExec enum_ca Module Discover Active Directory Certificate Services CA hosts on the network and grab basic CA information (name,…
- NetExec MS17-010 Check (EternalBlue) Detect MS17-010 (EternalBlue) vulnerable hosts via the SMBv1 transaction probe. Safe scan only —…
- NetExec Password Policy Enumerate Domain Password Policy
- NetExec SMB Enumerate AV Enumerate installed antivirus and security products on remote hosts
- NetExec SMB Enumerate Groups Enumerate domain groups via SMB
- NetExec SMB Enumerate Users Enumerate domain users via SMB
- NetExec SMB Get Network Retrieve network interface and configuration information from remote hosts
- NetExec SMB Logged-On Users Enumerate currently logged-on users on remote hosts
- NetExec SMB RunAsPPL Check Check if LSA Protection (RunAsPPL) is enabled on remote hosts
- NetExec SMB Shares Enumerate SMB shares
- NetExec SMB Spider Spider SMB shares for files and optionally download them
- NetExec SMB UAC Status Check UAC (User Account Control) configuration on remote hosts
- NetExec spider_plus Module Recursively spider every readable share, indexing filenames, sizes, modification dates, and (optionally)…
- NetExec Zerologon Check (CVE-2020-1472) Non-destructive check for the Netlogon CVE-2020-1472 (Zerologon) vulnerability against a domain controller.…
- RPCClient Enum Domain Users Enumerate domain users via RPC using rpcclient
- SMBClient Interactive Interactive SMB client for browsing and downloading files from shares
- SMBMap Share Enumeration SMB share enumeration and access testing
LDAP 30
- BloodHound AD Collection Collect Active Directory data for BloodHound analysis
- bloodyAD get children List the immediate children of a container or OU. Handy for walking the directory tree without firing a full…
- bloodyAD get dnsDump Dump every AD-integrated DNS record from the domain. Authenticated users can read most zones by default —…
- bloodyAD get membership Recursively resolve every group a principal belongs to, including nested groups. Faster than chasing…
- bloodyAD Get Object Attributes Read all (or specific) LDAP attributes of an AD object. Useful for confirming…
- bloodyAD get search Run an arbitrary LDAP filter against the directory and pull selected attributes. The escape hatch when none…
- bloodyAD get trusts Enumerate domain and forest trust relationships, including direction, type, and trust attributes. Quick…
- bloodyAD get writable Enumerate every AD object the current principal can write to — fastest path to finding ACL escalation…
- Impacket findDelegation Find all accounts with delegation rights (unconstrained, constrained, RBCD)
- Impacket GetADComputers Enumerate all Active Directory computer accounts
- Impacket GetADUsers Enumerate all Active Directory user accounts
- LDAP Anonymous Bind LDAP Anonymous Bind
- LDAP User Enumeration Extract all domain users and save to users.txt
- LDAPDomainDump Dump domain information via LDAP into HTML, JSON, and grep-friendly formats
- NetExec daclread Module Read the DACL of an arbitrary AD object via LDAP and resolve every ACE to a human-readable principal/right…
- NetExec LDAP ADCS Enumeration Enumerate ADCS certificate authorities and templates via NetExec
- NetExec LDAP AdminCount Users Enumerate accounts with adminCount=1 (protected admin accounts) via LDAP
- NetExec LDAP BloodHound Collect BloodHound data via NetExec LDAP module
- NetExec LDAP DC List Enumerate all Domain Controllers in the domain via LDAP
- NetExec LDAP Enumerate CA Enumerate Certificate Authority (CA) servers in Active Directory
- NetExec LDAP Enumerate DNS Enumerate DNS zones and records stored in Active Directory via LDAP
- NetExec LDAP Enumerate Subnets Enumerate AD Sites and Services subnets from Active Directory
- NetExec LDAP Enumerate Trusts Enumerate domain trust relationships via LDAP
- NetExec LDAP Find Delegation Find all accounts with delegation rights via LDAP
- NetExec LDAP Machine Account Quota Check the Machine Account Quota (ms-DS-MachineAccountQuota) for the domain
- NetExec LDAP MSOL Account Retrieve the cleartext password of the MSOL (Azure AD Connect) sync account
- NetExec LDAP Signing Checker Check if LDAP signing and channel binding are enforced on the domain controller
- NetExec LDAP User Descriptions Extract user account descriptions via LDAP
- NetExec pre2k Module Enumerate computer accounts that still use the pre-Windows-2000 compatible access default password (the…
- RustHound BloodHound Collection Collect Active Directory data for BloodHound using RustHound (Kerberos-aware)
Kerberos 1
- Kerbrute User Enumeration Kerberos user enumeration without authentication
DNS 3
- ADIDNSDump Dump all DNS records from Active Directory integrated DNS zones
- DNS SRV Record Lookup Query DNS SRV records to discover domain controllers and services
- Krbrelayx DNSTool Add, modify, or query DNS records in Active Directory integrated DNS
WinRM 2
- NetExec WinRM User Enum Enumerate domain users via WinRM after a successful auth. Equivalent to the SMB --users flag but uses…
- NetExec WMI Query Run an arbitrary WQL query over WMI without dropping into wmic / Get-WmiObject. Useful for live process…
MSSQL 3
- NetExec MSSQL enum_impersonate List every login the current user can EXECUTE AS (IMPERSONATE permission). The classic privesc primitive on…
- NetExec MSSQL enum_logins List every SQL Server login (built-in sa, Windows-mapped accounts, contained DB users) on the instance. Pair…
- NetExec MSSQL Query Run an arbitrary SQL query against MSSQL via NetExec. Faster than firing up impacket-mssqlclient when you…
SSH 2
- NetExec SSH Command Exec Spray a command across many SSH targets. Faster than scripting ssh in a loop and inherits all of nxc's…
- NetExec SSH Key Auth Validate a recovered SSH private key against one or many hosts. Automatically detects passphrase-protected…
FTP 1
- NetExec FTP List Files List the contents of an FTP server's working directory (or a specified path). Quick triage step before…
NFS 1
- NetExec NFS Share Enumeration Enumerate exported NFS shares on a host. Combine with --enum-shares to recursively list contents of…
BloodHound Cypher Queries 10
- BloodHound.py CE Collector Collect AD data into the BloodHound Community Edition JSON format from Linux. Use --zip for a single…
- Cypher: ADCS ESC1 Candidates (Certipy BloodHound) List every user that can enroll in an ESC1-vulnerable certificate template (enrollee supplies subject +…
- Cypher: All Paths from Owned to High-Value All shortest paths from any owned principal to any high-value target (Domain Admins, Enterprise Admins, DCs,…
- Cypher: AS-REP Roastable Users List every user with DONT_REQ_PREAUTH set — these accounts can be AS-REP roasted without prior…
- Cypher: Kerberoastable Users List every kerberoastable user in the domain (has a SPN, not krbtgt). Pair with hasLAPS / admincount /…
- Cypher: Principals With DCSync Rights Find every principal that holds DS-Replication-Get-Changes / DS-Replication-Get-Changes-All on the domain…
- Cypher: RBCD Write Targets Surface every account that can write to a computer object — the precondition for Resource-Based Constrained…
- Cypher: Shortest Path to Domain Admins Find the shortest attack path from any owned user to the Domain Admins group. The bread-and-butter…
- Cypher: Unconstrained Delegation Find every computer or user with TRUSTED_FOR_DELEGATION set, excluding the DCs themselves. Coercing a…
- RustHound-CE Collector Faster Rust-based BloodHound CE collector. Single static binary, ideal when Python isn't available or LDAP…