Active Directory
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Windows/Samba hosts with open SMB — users, shares, policies.
How
Point at IP; try null/guest/authenticated sessions.
Why
Classic first enum step on SMB.
Commands & usage
enum4linux-ng -A 192.168.1.10
enum4linux-ng -u user -p pass 192.168.1.10
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Recipes
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
SMBMap
Enumerates Samba share drives across networks with permissions.
ldapsearch / windapsearch
Query LDAP/Active Directory directory data.