Password Spraying - Making a Target User List ACTIVE Directory
By leveraging an SMB NULL session
retrieve a complete list of domain users from the domain controller
Utilizing an LDAP anonymous bind to query LDAP anonymously
pull down the domain user list
Use tool such as
Using enum4linux
SMB NULL Session to Pull User List
Using rpcclient
SMB NULL Session to Pull User List
Using CrackMapExec --users Flag
SMB NULL Session to Pull User List
Gathering Users with LDAP Anonymous
Some examples include windapsearch and ldapsearch.
Using ldapsearch
Using windapsearch
Enumerating Users with Kerbrute
look into statistically-likely-usernames for username list
jsmith.txt is from this list
Credentialed Enumeration to Build our User List
With valid credentials,
can use any of the tools stated previously to build a user list. A quick and easy way is using CrackMapExec.
Using CrackMapExec with Valid Credentials
Last updated