rpcclient-enumeration.md (10650B)
1 --- 2 title: "rpcclient enumeration" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-smb/rpcclient-enumeration.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smb/rpcclient-enumeration.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # rpcclient enumeration 14 15 ### Overview of Relative Identifiers (RID) and Security Identifiers (SID) 16 17 Windows uses **security identifiers (SIDs)** to identify security principals. For domain accounts, the final subauthority is the **relative identifier (RID)** allocated within that domain.<sup>[[1]](#references)</sup> 18 19 - A domain has a domain SID. 20 - Appending an account's RID to that domain SID forms the account SID. 21 22 For instance, a user named `pepe` might have a unique identifier combining the domain's SID with his specific RID, represented in both hexadecimal (`0x457`) and decimal (`1111`) formats. This results in a complete and unique identifier for pepe within the domain like: `S-1-5-21-1074507654-1937615267-42093643874-1111`. 23 24 ### **Enumeration with rpcclient** 25 26 Samba's **`rpcclient`** interacts with RPC interfaces over SMB named pipes. The commands below target SAMR, LSARPC, and related interfaces after an SMB session is established; anonymous availability depends on server policy.<sup>[[2]](#references)</sup> 27 28 #### Authentication, transport and command batching 29 30 Use `-c` with semicolon-separated commands to reuse one authenticated session. Current Samba clients can use a password, an NT hash, or a Kerberos credential cache; Kerberos requires the service hostname rather than only an IP. `-I` is useful when DNS must be retained for the SPN but the address must be pinned. `--client-protection=sign|encrypt` can explicitly request SMB signing or encryption.<sup>[[2]](#references)</sup> 31 32 ```bash 33 # Null session 34 rpcclient -N -U '' <target> -c 'srvinfo;enumdomains;lsaquery' 35 36 # NTLM (omit %password to be prompted) or pass-the-hash 37 rpcclient -U 'DOMAIN/user' <target> 38 rpcclient --pw-nt-hash -U 'DOMAIN/user%<NT_HASH>' <target> 39 40 # Kerberos ccache; keep the FQDN for the SPN and optionally pin its IP 41 rpcclient --use-krb5-ccache="$KRB5CCNAME" -I <target_ip> dc.example.com -c 'enumdomusers;enumdomgroups' 42 ``` 43 44 Avoid placing cleartext passwords directly in the command line. Prompt for them or use `-A <auth-file>` with restrictive permissions; the authentication-file format accepts `username`, `password`, and `domain` entries.<sup>[[2]](#references)</sup> 45 46 #### Server Information 47 48 - To obtain **Server Information**: `srvinfo` command is used. 49 - To confirm the identity associated with the session: `getusername`.<sup>[[2]](#references)</sup> 50 - To query the server's time: `netremotetod`.<sup>[[2]](#references)</sup> 51 52 #### Enumeration of Users 53 54 - **Users can be listed** using: `querydispinfo` and `enumdomusers`. 55 - **Details of a user** by: `queryuser <0xrid>`. 56 - **Groups of a user** with: `queryusergroups <0xrid>`. 57 - **A user's SID is retrieved** through: `lookupnames <username>`. 58 - **Aliases of users** by: `queryuseraliases builtin|domain <sid1> [sid2 ...]`. 59 60 `querydispinfo` is especially useful because its output can include the account name, full name and description, while `queryuser` exposes timestamps and account-control information for a specific RID. Review descriptions for operational notes or accidentally stored secrets.<sup>[[2]](#references)</sup> 61 62 ```bash 63 # Users' RIDs-forced (one SAMR query per RID) 64 for i in $(seq 500 1100); do 65 rpcclient -N -U "" [IP_ADDRESS] -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name\|user_rid\|group_rid" && echo ""; 66 done 67 68 # samrdump.py can also serve this purpose 69 ``` 70 71 #### Password policy and per-account password data 72 73 `getdompwinfo <DOMAIN>` returns the minimum password length and password-property flags exposed by SAMR. `getusrdompwinfo <0xRID>` queries password information associated with one user handle. These calls do not necessarily expose the complete effective domain policy, and access can differ between Windows and Samba targets.<sup>[[2]](#references)</sup> 74 75 ```bash 76 rpcclient -U 'DOMAIN/user' <target> -c 'getdompwinfo DOMAIN;getusrdompwinfo 0x1f4' 77 ``` 78 79 Before password guessing, obtain the effective lockout policy through the broader SMB/LDAP enumeration workflow; SAMR guessing can still lock accounts. See [Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying). 80 81 #### Enumeration of Groups 82 83 - **Groups** by: `enumdomgroups`. 84 - **Details of a group** with: `querygroup <0xrid>`. 85 - **Members of a group** through: `querygroupmem <0xrid>`. 86 - Resolve several returned member RIDs in one request with: `samlookuprids domain <rid1> <rid2> ...`.<sup>[[2]](#references)</sup> 87 88 ```bash 89 rpcclient -U 'DOMAIN/user' <target> -c 'querygroupmem 0x200;samlookuprids domain 0x1f4 0x44f' 90 ``` 91 92 #### Enumeration of Alias Groups 93 94 - **Alias groups** by: `enumalsgroups <builtin|domain>`. 95 - **Members of an alias group** with: `queryaliasmem builtin|domain <0xrid>`. 96 - **Alias details** with: `queryaliasinfo builtin|domain <0xrid>`.<sup>[[2]](#references)</sup> 97 98 #### Enumeration of Domains and Trusts 99 100 - **Domains** using: `enumdomains`. 101 - **A domain's SID is retrieved** through: `lsaquery`. 102 - **Domain information is obtained** by: `querydominfo`. 103 - **Trust relationships** can be queried with `enumtrust` and, on AD targets, `dsenumdomtrusts`.<sup>[[2]](#references)</sup> 104 105 #### Enumeration of Shares and Active Use 106 107 - **All available shares** by: `netshareenumall`. 108 - **Information about a specific share is fetched** with: `netsharegetinfo <share>`. 109 - **Sessions, open files and connections** can be requested with `netsessenum`, `netfileenum`, and `netconnenum`; these commonly require more privilege than share listing.<sup>[[2]](#references)</sup> 110 111 #### Additional Operations with SIDs 112 113 - **SIDs by name** using: `lookupnames <name1> <name2> ...`. 114 - **More SIDs** through: `lsaenumsid`. 115 - **RID cycling to check more SIDs** is performed by: `lookupsids <sid1> <sid2> ...`. 116 117 SAMR enumeration and LSARPC SID translation have separate access checks. Therefore, if `enumdomusers` is denied, test whether a known principal can still reveal a base SID with `lookupnames`, then submit multiple candidate SIDs to `lookupsids`. Batching avoids reconnecting for every RID and is substantially faster than the `queryuser` loop above. `enum4linux-ng` implements this approach; RID cycling is opt-in with `-R`, accepts a batch size, and allows explicit ranges with `-r`.<sup>[[2]](#references)[[4]](#references)</sup> 118 119 ```bash 120 # Direct LSARPC batch after obtaining the account-domain SID 121 rpcclient -N -U '' <target> -c 'lookupsids S-1-5-21-...-500 S-1-5-21-...-501 S-1-5-21-...-1000' 122 123 # Automated batched RID cycling (null credentials by default) 124 enum4linux-ng -R 100 -r 500-550,1000-2000 <target> 125 ``` 126 127 On a domain member, distinguish the machine/account-domain SID from the AD domain SID. Validate the prefix by resolving a known local account and a known domain account before cycling it.<sup>[[2]](#references)[[4]](#references)</sup> 128 129 #### Privileges and account rights 130 131 With sufficient policy access, `enumprivs` lists known privileges, while `lsaenumacctrights <SID>` and `lsaenumprivsaccount <SID>` reveal rights assigned to a principal. This can identify service-logon assignments and other interesting local-policy grants without changing them.<sup>[[2]](#references)</sup> 132 133 #### **Extra commands** 134 135 The following command/interface mapping follows the current `rpcclient` command inventory.<sup>[[2]](#references)</sup> 136 137 | **Command** | **Interface** | **Description** | 138 | ----------- | ------------- | --------------- | 139 | `queryuser` | SAMR | Retrieve user information | 140 | `querygroup` | SAMR | Retrieve group information | 141 | `querydominfo` | SAMR | Retrieve domain information | 142 | `enumdomusers` | SAMR | Enumerate domain users | 143 | `enumdomgroups` | SAMR | Enumerate domain groups | 144 | `samlookuprids domain <rids...>` | SAMR | Resolve several domain RIDs in one request | 145 | `getdompwinfo <domain>` | SAMR | Retrieve exposed domain password information | 146 | `getusrdompwinfo <rid>` | SAMR | Retrieve password information for a user handle | 147 | `createdomuser` | SAMR | Create a domain user (requires permission) | 148 | `deletedomuser` | SAMR | Delete a domain user (requires permission) | 149 | `lookupnames` | LSARPC | Resolve names to SID values | 150 | `lookupsids` | LSARPC | Resolve SIDs to names; useful for batched RID cycling | 151 | `lsaenumacctrights` | LSARPC | Enumerate rights assigned to an SID | 152 | `lsaaddacctrights` | LSARPC | Add account rights (requires permission) | 153 | `lsaremoveacctrights` | LSARPC | Remove rights from an account (requires permission) | 154 | `netsessenum` | SRVSVC | Enumerate SMB sessions (often privileged) | 155 | `netfileenum` | SRVSVC | Enumerate remotely open files (often privileged) | 156 | `dsroledominfo` | LSARPC-DS | Get primary-domain information | 157 | `dsenumdomtrusts` | LSARPC-DS | Enumerate trusted domains in an AD forest | 158 159 Commands such as `createdomuser`, `deletedomuser`, `lsaaddacctrights`, and `lsaremoveacctrights` mutate the target and are not enumeration primitives; use them only when explicitly authorized.<sup>[[2]](#references)</sup> 160 161 For related `samrdump` and `rpcdump` workflows, see [Pentesting MSRPC](/hacktricks/network-services-pentesting/135-pentesting-msrpc); the broader assessment reference also contextualizes RID cycling and null-session enumeration.<sup>[[3]](#references)</sup> 162 163 #### Detection note 164 165 Modern Defender for Identity/Defender XDR exposes an **Anomalous SAMR activity** detection mapped to account and permission-group discovery (MITRE ATT&CK T1087 and T1069). Operationally, large RID ranges and repeated SAMR/LSARPC queries should be treated as detectable reconnaissance, even when the server permits them.<sup>[[5]](#references)</sup> 166 167 168 ## References 169 170 - [1] [Microsoft - Security identifiers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers) 171 - [2] [Samba `rpcclient(1)` manual](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html) 172 - [3] [Network Security Assessment, 3rd Edition – Chapter 8](https://learning.oreilly.com/library/view/network-security-assessment/9781491911044/ch08.html) 173 - [4] [enum4linux-ng](https://github.com/cddmp/enum4linux-ng) 174 - [5] [Microsoft Defender for Identity alerts in Microsoft Defender format](https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr)