Rpcclient
Without Crendentials
Null Sesion Rpcclient Enum Users
rpcclient -U "" <DC_IP> -N -c "enumdomusers"With Crendentials
Enumeration All Domain Users
rpcclient -U "deimcorp.local\champi%Password2" <AD_IP> -c "enumdomusers"Enumeration Description All Domain Users
for rid in $(rpcclient -U "deimcorp.local\champi%Password2" <DC-IP> -c "enumdomusers" | grep -oP 'rid:\[0x[0-9a-fA-F]+\]' | tr -d '[]' | awk -F: '{print $2}'); do echo -e "\n[*] RID: $rid:\n"; rpcclient -U "deimcorp.local\champi%Password2" <DC-IP> -c "queryuser $rid" | grep -E -i "user name|description" ;done
Enumeration All Admins Users
Last updated