SMB Enumeration Guide: Discovering Windows Shares and Users
Complete guide to SMB enumeration for discovering Windows shares, users, groups, and network resources using Enum4Linux, SMBClient, NBTScan, and Nmap.
Why SMB Enumeration Matters
You have found ports 139 or 445 open on a target — SMB enumeration reveals shares, users, groups, and password policies that can lead to full compromise. It is one of the most fruitful information-gathering steps in Windows and Active Directory penetration testing.
Prerequisites
Before performing SMB enumeration, ensure you have:
How SMB Enumeration Works
SMB enumeration works by establishing connections to the target's SMB service and querying various information classes. The process typically follows these stages:
Share Discovery: Lists all available shared resources on the target including disk shares (files), IPC shares (inter-process communication), and print shares (printers).
User Enumeration: Extracts local user accounts through SAM database queries, RID cycling, and policy enumeration techniques.
Group Enumeration: Identifies local group memberships and privileged groups like Administrators and Remote Desktop Users.
Policy Analysis: Retrieves password complexity requirements, lockout thresholds, and account restrictions.
Installation
All tools in this guide are pre-installed on Kali Linux:
# Verify installation
enum4linux --version
smbclient --version
nbtscan --version
On other distributions:
# Debian/Ubuntu
sudo apt install enum4linux smbclient nbtscan
# RHEL/CentOS
sudo yum install enum4linux samba-client nbtscan
Step 1: Host Discovery with Netdiscover
Before enumerating SMB services, identify live hosts on the network:
# Discover hosts via ARP
netdiscover -r 192.168.1.0/24
# Or use Nmap ping sweep
nmap -sn 192.168.1.0/24
Step 2: Verify SMB Ports with Nmap
Confirm SMB is running on discovered hosts:
# Check SMB ports
nmap -p 139,445 192.168.1.0/24
# Detect SMB version
nmap -p 445 --script smb-os-discovery 192.168.1.10
Step 3: Quick NetBIOS Scan with NBTScan
快速 NetBIOS name resolution across the network:
# Scan subnet for NetBIOS names
nbtscan 192.168.1.0/24
# Verbose output
nbtscan -v 192.168.1.0/24
The output shows IP addresses, NetBIOS names, workgroups, and MAC addresses for each discovered host.
Step 4: Comprehensive Enumeration with Enum4Linux
Run full enumeration on each discovered host:
# Full enumeration (users, groups, shares, policies)
enum4linux -a 192.168.1.10
# User enumeration only
enum4linux -U 192.168.1.10
# Share enumeration only
enum4linux -S 192.168.1.10
# Password policy
enum4linux -P 192.168.1.10
# Authenticated enumeration
enum4linux -a -u admin -p password123 192.168.1.10
Step 5: Share Access Testing with SMBClient
After Enum4Linux discovers shares, test each one for access:
# List shares anonymously
smbclient -L //192.168.1.10 -N
# Connect to a share with credentials
smbclient //192.168.1.10/public -U admin%password123
# Browse share contents
smb: \> ls
smb: \> cd subfolder
smb: \> get filename.txt
# Download all files recursively
smb: \> recurse on
smb: \> mget *
Step 6: Automate with CrackMapExec
For large networks, automate enumeration across all hosts:
# Test credentials across subnet
crackmapexec smb 192.168.1.0/24 -u admin -p password123
# Enumerate shares on all authenticated hosts
crackmapexec smb 192.168.1.0/24 -u admin -p password123 --shares
# Extract user lists
crackmapexec smb 192.168.1.0/24 -u admin -p password123 --users
Interpreting Results
Share Types: Disk shares contain files, IPC shares are for named pipe communication, Print shares represent shared printers. Focus on Disk shares for data access.
User Accounts: Note RID 500 (Administrator), RID 501 (Guest), and any custom accounts. Guest accounts often have weak or no passwords.
Password Policies: Lockout threshold determines brute-force feasibility. If lockout is disabled, password attacks are unlimited.
Permissions: NT_STATUS_ACCESS_DENIED means the share exists but requires authentication. Anonymous access means the share allows null sessions.
Common Mistakes
Best Practices
Related Tools
Related Articles
Learning Roadmap
Summary
SMB enumeration is the foundation of Windows network security assessment. By systematically discovering hosts, listing shares, extracting users, and analyzing policies, you build a complete picture of the target environment. Always follow the workflow: discover hosts → verify ports → enumerate shares → test access → document findings.