No Credentials
No Credentials
Network Scanning
Scan Network
nmap -sP -p -Pn <ip>
nmap -Pn -sV --top-ports 50 --open <ip>
nmap -Pn --script-smb-vuln -p139,445 <ip>
nmap -Pn -sC -sV -oN <OutPutFile> <ip>
nmap -Pn -sC -sV -p- -oN <OutPutFile> <ip>
nmap -Pn -sU -sC -sV -oN <OutPutFile> <ip>
nmap -n -sV --script "ldap* and not brute" -p 389 <DC IP>SNMP Check
snmp-check 10.10.31.2 -c openviewCME
#Map Hosts
cme smb 192.168.1.0/24
#Map SMB hosts that DO NOT require signing
cme smb 192.168.1.0/24 --gen-relay-list relaylistOutputFilename.txt
#Enumerate Null Sessions
cme smb 10.10.10.161 -u '' -p ''
cme smb 10.10.10.161 --pass-pol
cme smb 10.10.10.161 --users
cme smb 10.10.10.161 --groups
#Enumerate Anonymous Login
cme smb 10.10.10.178 -u 'a' -p ''
#Extract Subnet
cme ldap <ip> -u <user> -p <pass> -M get-network
cme ldap <ip> -u <user> -p <pass> -M get-network -o ONLY_HOSTS=true
cme ldap <ip> -u <user> -p <pass> -M get-network -o ALL=trueGoBuster
Find DC IP
Zone Transfer
LDAP Search
wfuzz vhost discovery
List Guest Access on SMB Share
Enumerate Users
CME
Kerbrute
Impacket
NMAP
MetaSploit
SMBmap
Rubeus
NTLMRelay
Last updated