daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

rpcclient-enumeration.md (10650B)


      1 ---
      2 title: "rpcclient enumeration"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-smb/rpcclient-enumeration.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-smb/rpcclient-enumeration.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # rpcclient enumeration
     14 
     15 ### Overview of Relative Identifiers (RID) and Security Identifiers (SID)
     16 
     17 Windows uses **security identifiers (SIDs)** to identify security principals. For domain accounts, the final subauthority is the **relative identifier (RID)** allocated within that domain.<sup>[[1]](#references)</sup>
     18 
     19 - A domain has a domain SID.
     20 - Appending an account's RID to that domain SID forms the account SID.
     21 
     22 For instance, a user named `pepe` might have a unique identifier combining the domain's SID with his specific RID, represented in both hexadecimal (`0x457`) and decimal (`1111`) formats. This results in a complete and unique identifier for pepe within the domain like: `S-1-5-21-1074507654-1937615267-42093643874-1111`.
     23 
     24 ### **Enumeration with rpcclient**
     25 
     26 Samba's **`rpcclient`** interacts with RPC interfaces over SMB named pipes. The commands below target SAMR, LSARPC, and related interfaces after an SMB session is established; anonymous availability depends on server policy.<sup>[[2]](#references)</sup>
     27 
     28 #### Authentication, transport and command batching
     29 
     30 Use `-c` with semicolon-separated commands to reuse one authenticated session. Current Samba clients can use a password, an NT hash, or a Kerberos credential cache; Kerberos requires the service hostname rather than only an IP. `-I` is useful when DNS must be retained for the SPN but the address must be pinned. `--client-protection=sign|encrypt` can explicitly request SMB signing or encryption.<sup>[[2]](#references)</sup>
     31 
     32 ```bash
     33 # Null session
     34 rpcclient -N -U '' <target> -c 'srvinfo;enumdomains;lsaquery'
     35 
     36 # NTLM (omit %password to be prompted) or pass-the-hash
     37 rpcclient -U 'DOMAIN/user' <target>
     38 rpcclient --pw-nt-hash -U 'DOMAIN/user%<NT_HASH>' <target>
     39 
     40 # Kerberos ccache; keep the FQDN for the SPN and optionally pin its IP
     41 rpcclient --use-krb5-ccache="$KRB5CCNAME" -I <target_ip> dc.example.com -c 'enumdomusers;enumdomgroups'
     42 ```
     43 
     44 Avoid placing cleartext passwords directly in the command line. Prompt for them or use `-A <auth-file>` with restrictive permissions; the authentication-file format accepts `username`, `password`, and `domain` entries.<sup>[[2]](#references)</sup>
     45 
     46 #### Server Information
     47 
     48 - To obtain **Server Information**: `srvinfo` command is used.
     49 - To confirm the identity associated with the session: `getusername`.<sup>[[2]](#references)</sup>
     50 - To query the server's time: `netremotetod`.<sup>[[2]](#references)</sup>
     51 
     52 #### Enumeration of Users
     53 
     54 - **Users can be listed** using: `querydispinfo` and `enumdomusers`.
     55 - **Details of a user** by: `queryuser <0xrid>`.
     56 - **Groups of a user** with: `queryusergroups <0xrid>`.
     57 - **A user's SID is retrieved** through: `lookupnames <username>`.
     58 - **Aliases of users** by: `queryuseraliases builtin|domain <sid1> [sid2 ...]`.
     59 
     60 `querydispinfo` is especially useful because its output can include the account name, full name and description, while `queryuser` exposes timestamps and account-control information for a specific RID. Review descriptions for operational notes or accidentally stored secrets.<sup>[[2]](#references)</sup>
     61 
     62 ```bash
     63 # Users' RIDs-forced (one SAMR query per RID)
     64 for i in $(seq 500 1100); do
     65     rpcclient -N -U "" [IP_ADDRESS] -c "queryuser 0x$(printf '%x\n' $i)" | grep "User Name\|user_rid\|group_rid" && echo "";
     66 done
     67 
     68 # samrdump.py can also serve this purpose
     69 ```
     70 
     71 #### Password policy and per-account password data
     72 
     73 `getdompwinfo <DOMAIN>` returns the minimum password length and password-property flags exposed by SAMR. `getusrdompwinfo <0xRID>` queries password information associated with one user handle. These calls do not necessarily expose the complete effective domain policy, and access can differ between Windows and Samba targets.<sup>[[2]](#references)</sup>
     74 
     75 ```bash
     76 rpcclient -U 'DOMAIN/user' <target> -c 'getdompwinfo DOMAIN;getusrdompwinfo 0x1f4'
     77 ```
     78 
     79 Before password guessing, obtain the effective lockout policy through the broader SMB/LDAP enumeration workflow; SAMR guessing can still lock accounts. See [Password Spraying](/hacktricks/windows-hardening/active-directory-methodology/password-spraying).
     80 
     81 #### Enumeration of Groups
     82 
     83 - **Groups** by: `enumdomgroups`.
     84 - **Details of a group** with: `querygroup <0xrid>`.
     85 - **Members of a group** through: `querygroupmem <0xrid>`.
     86 - Resolve several returned member RIDs in one request with: `samlookuprids domain <rid1> <rid2> ...`.<sup>[[2]](#references)</sup>
     87 
     88 ```bash
     89 rpcclient -U 'DOMAIN/user' <target> -c 'querygroupmem 0x200;samlookuprids domain 0x1f4 0x44f'
     90 ```
     91 
     92 #### Enumeration of Alias Groups
     93 
     94 - **Alias groups** by: `enumalsgroups <builtin|domain>`.
     95 - **Members of an alias group** with: `queryaliasmem builtin|domain <0xrid>`.
     96 - **Alias details** with: `queryaliasinfo builtin|domain <0xrid>`.<sup>[[2]](#references)</sup>
     97 
     98 #### Enumeration of Domains and Trusts
     99 
    100 - **Domains** using: `enumdomains`.
    101 - **A domain's SID is retrieved** through: `lsaquery`.
    102 - **Domain information is obtained** by: `querydominfo`.
    103 - **Trust relationships** can be queried with `enumtrust` and, on AD targets, `dsenumdomtrusts`.<sup>[[2]](#references)</sup>
    104 
    105 #### Enumeration of Shares and Active Use
    106 
    107 - **All available shares** by: `netshareenumall`.
    108 - **Information about a specific share is fetched** with: `netsharegetinfo <share>`.
    109 - **Sessions, open files and connections** can be requested with `netsessenum`, `netfileenum`, and `netconnenum`; these commonly require more privilege than share listing.<sup>[[2]](#references)</sup>
    110 
    111 #### Additional Operations with SIDs
    112 
    113 - **SIDs by name** using: `lookupnames <name1> <name2> ...`.
    114 - **More SIDs** through: `lsaenumsid`.
    115 - **RID cycling to check more SIDs** is performed by: `lookupsids <sid1> <sid2> ...`.
    116 
    117 SAMR enumeration and LSARPC SID translation have separate access checks. Therefore, if `enumdomusers` is denied, test whether a known principal can still reveal a base SID with `lookupnames`, then submit multiple candidate SIDs to `lookupsids`. Batching avoids reconnecting for every RID and is substantially faster than the `queryuser` loop above. `enum4linux-ng` implements this approach; RID cycling is opt-in with `-R`, accepts a batch size, and allows explicit ranges with `-r`.<sup>[[2]](#references)[[4]](#references)</sup>
    118 
    119 ```bash
    120 # Direct LSARPC batch after obtaining the account-domain SID
    121 rpcclient -N -U '' <target> -c 'lookupsids S-1-5-21-...-500 S-1-5-21-...-501 S-1-5-21-...-1000'
    122 
    123 # Automated batched RID cycling (null credentials by default)
    124 enum4linux-ng -R 100 -r 500-550,1000-2000 <target>
    125 ```
    126 
    127 On a domain member, distinguish the machine/account-domain SID from the AD domain SID. Validate the prefix by resolving a known local account and a known domain account before cycling it.<sup>[[2]](#references)[[4]](#references)</sup>
    128 
    129 #### Privileges and account rights
    130 
    131 With sufficient policy access, `enumprivs` lists known privileges, while `lsaenumacctrights <SID>` and `lsaenumprivsaccount <SID>` reveal rights assigned to a principal. This can identify service-logon assignments and other interesting local-policy grants without changing them.<sup>[[2]](#references)</sup>
    132 
    133 #### **Extra commands**
    134 
    135 The following command/interface mapping follows the current `rpcclient` command inventory.<sup>[[2]](#references)</sup>
    136 
    137 | **Command** | **Interface** | **Description** |
    138 | ----------- | ------------- | --------------- |
    139 | `queryuser` | SAMR | Retrieve user information |
    140 | `querygroup` | SAMR | Retrieve group information |
    141 | `querydominfo` | SAMR | Retrieve domain information |
    142 | `enumdomusers` | SAMR | Enumerate domain users |
    143 | `enumdomgroups` | SAMR | Enumerate domain groups |
    144 | `samlookuprids domain <rids...>` | SAMR | Resolve several domain RIDs in one request |
    145 | `getdompwinfo <domain>` | SAMR | Retrieve exposed domain password information |
    146 | `getusrdompwinfo <rid>` | SAMR | Retrieve password information for a user handle |
    147 | `createdomuser` | SAMR | Create a domain user (requires permission) |
    148 | `deletedomuser` | SAMR | Delete a domain user (requires permission) |
    149 | `lookupnames` | LSARPC | Resolve names to SID values |
    150 | `lookupsids` | LSARPC | Resolve SIDs to names; useful for batched RID cycling |
    151 | `lsaenumacctrights` | LSARPC | Enumerate rights assigned to an SID |
    152 | `lsaaddacctrights` | LSARPC | Add account rights (requires permission) |
    153 | `lsaremoveacctrights` | LSARPC | Remove rights from an account (requires permission) |
    154 | `netsessenum` | SRVSVC | Enumerate SMB sessions (often privileged) |
    155 | `netfileenum` | SRVSVC | Enumerate remotely open files (often privileged) |
    156 | `dsroledominfo` | LSARPC-DS | Get primary-domain information |
    157 | `dsenumdomtrusts` | LSARPC-DS | Enumerate trusted domains in an AD forest |
    158 
    159 Commands such as `createdomuser`, `deletedomuser`, `lsaaddacctrights`, and `lsaremoveacctrights` mutate the target and are not enumeration primitives; use them only when explicitly authorized.<sup>[[2]](#references)</sup>
    160 
    161 For related `samrdump` and `rpcdump` workflows, see [Pentesting MSRPC](/hacktricks/network-services-pentesting/135-pentesting-msrpc); the broader assessment reference also contextualizes RID cycling and null-session enumeration.<sup>[[3]](#references)</sup>
    162 
    163 #### Detection note
    164 
    165 Modern Defender for Identity/Defender XDR exposes an **Anomalous SAMR activity** detection mapped to account and permission-group discovery (MITRE ATT&CK T1087 and T1069). Operationally, large RID ranges and repeated SAMR/LSARPC queries should be treated as detectable reconnaissance, even when the server permits them.<sup>[[5]](#references)</sup>
    166 
    167 
    168 ## References
    169 
    170 - [1] [Microsoft - Security identifiers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-identifiers)
    171 - [2] [Samba `rpcclient(1)` manual](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html)
    172 - [3] [Network Security Assessment, 3rd Edition – Chapter 8](https://learning.oreilly.com/library/view/network-security-assessment/9781491911044/ch08.html)
    173 - [4] [enum4linux-ng](https://github.com/cddmp/enum4linux-ng)
    174 - [5] [Microsoft Defender for Identity alerts in Microsoft Defender format](https://learn.microsoft.com/en-us/defender-for-identity/alerts-xdr)