GO KALI FREE
BeginnerTools

SMB Enumeration Guide: Discovering Windows Shares and Users

Complete guide to SMB enumeration for discovering Windows shares, users, groups, and network resources using Enum4Linux, SMBClient, NBTScan, and Nmap.

#smb#enumeration#windows#samba#shares#network reconnaissance#penetration testing

Why SMB Enumeration Matters

You have found ports 139 or 445 open on a target — SMB enumeration reveals shares, users, groups, and password policies that can lead to full compromise. It is one of the most fruitful information-gathering steps in Windows and Active Directory penetration testing.

Prerequisites

Before performing SMB enumeration, ensure you have:

  • A Linux system with Kali Linux or similar penetration testing distribution
  • Network access to the target systems on ports 139 and 445
  • Understanding of Windows networking concepts (workgroups, domains, shares)
  • Explicit written authorization to test the target network
  • How SMB Enumeration Works

    SMB enumeration works by establishing connections to the target's SMB service and querying various information classes. The process typically follows these stages:

    Share Discovery: Lists all available shared resources on the target including disk shares (files), IPC shares (inter-process communication), and print shares (printers).

    User Enumeration: Extracts local user accounts through SAM database queries, RID cycling, and policy enumeration techniques.

    Group Enumeration: Identifies local group memberships and privileged groups like Administrators and Remote Desktop Users.

    Policy Analysis: Retrieves password complexity requirements, lockout thresholds, and account restrictions.

    Installation

    All tools in this guide are pre-installed on Kali Linux:

    # Verify installation
    enum4linux --version
    smbclient --version
    nbtscan --version
    

    On other distributions:

    # Debian/Ubuntu
    sudo apt install enum4linux smbclient nbtscan
    
    # RHEL/CentOS
    sudo yum install enum4linux samba-client nbtscan
    

    Step 1: Host Discovery with Netdiscover

    Before enumerating SMB services, identify live hosts on the network:

    # Discover hosts via ARP
    netdiscover -r 192.168.1.0/24
    
    # Or use Nmap ping sweep
    nmap -sn 192.168.1.0/24
    

    Step 2: Verify SMB Ports with Nmap

    Confirm SMB is running on discovered hosts:

    # Check SMB ports
    nmap -p 139,445 192.168.1.0/24
    
    # Detect SMB version
    nmap -p 445 --script smb-os-discovery 192.168.1.10
    

    Step 3: Quick NetBIOS Scan with NBTScan

    快速 NetBIOS name resolution across the network:

    # Scan subnet for NetBIOS names
    nbtscan 192.168.1.0/24
    
    # Verbose output
    nbtscan -v 192.168.1.0/24
    

    The output shows IP addresses, NetBIOS names, workgroups, and MAC addresses for each discovered host.

    Step 4: Comprehensive Enumeration with Enum4Linux

    Run full enumeration on each discovered host:

    # Full enumeration (users, groups, shares, policies)
    enum4linux -a 192.168.1.10
    
    # User enumeration only
    enum4linux -U 192.168.1.10
    
    # Share enumeration only
    enum4linux -S 192.168.1.10
    
    # Password policy
    enum4linux -P 192.168.1.10
    
    # Authenticated enumeration
    enum4linux -a -u admin -p password123 192.168.1.10
    

    Step 5: Share Access Testing with SMBClient

    After Enum4Linux discovers shares, test each one for access:

    # List shares anonymously
    smbclient -L //192.168.1.10 -N
    
    # Connect to a share with credentials
    smbclient //192.168.1.10/public -U admin%password123
    
    # Browse share contents
    smb: \> ls
    smb: \> cd subfolder
    smb: \> get filename.txt
    
    # Download all files recursively
    smb: \> recurse on
    smb: \> mget *
    

    Step 6: Automate with CrackMapExec

    For large networks, automate enumeration across all hosts:

    # Test credentials across subnet
    crackmapexec smb 192.168.1.0/24 -u admin -p password123
    
    # Enumerate shares on all authenticated hosts
    crackmapexec smb 192.168.1.0/24 -u admin -p password123 --shares
    
    # Extract user lists
    crackmapexec smb 192.168.1.0/24 -u admin -p password123 --users
    

    Interpreting Results

    Share Types: Disk shares contain files, IPC shares are for named pipe communication, Print shares represent shared printers. Focus on Disk shares for data access.

    User Accounts: Note RID 500 (Administrator), RID 501 (Guest), and any custom accounts. Guest accounts often have weak or no passwords.

    Password Policies: Lockout threshold determines brute-force feasibility. If lockout is disabled, password attacks are unlimited.

    Permissions: NT_STATUS_ACCESS_DENIED means the share exists but requires authentication. Anonymous access means the share allows null sessions.

    Common Mistakes

  • Not testing anonymous access first before trying credentials
  • Ignoring the IPC$ share which can reveal user information via null sessions
  • Assuming all shares are accessible without checking permissions
  • Running enumeration against entire /16 networks without first identifying SMB hosts
  • Using default credentials without checking if they have been changed
  • Best Practices

  • Always start with passive discovery (ARP, ping sweep) before active enumeration
  • Test anonymous access before providing credentials
  • Save all output to files for later analysis: `enum4linux -a target > output.txt`
  • Use authenticated enumeration when possible for complete results
  • Document all accessible shares and their permission levels
  • Related Tools

  • [Enum4Linux](/tools/enum4linux) — Comprehensive SMB enumeration
  • [Enum4Linux-NG](/tools/enum4linux-ng) — Modern Python 3 rewrite
  • [SMBClient](/tools/smbclient) — Interactive share access
  • [NBTScan](/tools/nbtscan) — Fast NetBIOS discovery
  • [Nmap](/tools/nmap) — Port scanning and service detection
  • [CrackMapExec](/tools/crackmapexec) — Large-scale SMB attacks
  • [Hydra](/tools/hydra) — Password brute-force attacks
  • Related Articles

  • [SMB Enumeration Complete Guide](/learn/smb-enumeration-complete-guide) — Beginner to advanced SMB workflow
  • [Enum4Linux Guide](/learn/enum4linux-guide) — Detailed Enum4Linux tutorial
  • [Windows Reconnaissance Basics](/learn/windows-reconnaissance-basics) — Windows network fundamentals
  • [Active Directory Fundamentals](/learn/active-directory-fundamentals) — AD enumeration techniques
  • Learning Roadmap

  • Start with [Nmap](/tools/nmap) to discover SMB-enabled hosts
  • Use [NBTScan](/tools/nbtscan) for quick NetBIOS name resolution
  • Run [Enum4Linux](/tools/enum4linux) for comprehensive enumeration
  • Test shares with [SMBClient](/tools/smbclient) for interactive access
  • Scale attacks with [CrackMapExec](/tools/crackmapexec) for network-wide operations
  • Brute-force passwords with [Hydra](/tools/hydra) using discovered usernames
  • Summary

    SMB enumeration is the foundation of Windows network security assessment. By systematically discovering hosts, listing shares, extracting users, and analyzing policies, you build a complete picture of the target environment. Always follow the workflow: discover hosts → verify ports → enumerate shares → test access → document findings.

    Related SMB Tool Recommendations

  • [SMBClient](/tools/smbclient) — Verify share access and browse discovered SMB shares
  • [Enum4Linux](/tools/enum4linux) — Enumerate SMB users, groups, shares, and policies
  • [Enum4Linux-NG](/tools/enum4linux-ng) — Run modern SMB enumeration with structured output
  • [NBTScan](/tools/nbtscan) — Resolve NetBIOS names before deeper SMB testing
  • [CrackMapExec](/tools/crackmapexec) — Scale SMB enumeration across larger networks
  • [NetExec](/tools/netexec) — Use modern SMB and Active Directory automation
  • Knowledge Check

  • What are the two SMB ports and which is preferred for modern systems?
  • What does the IPC$ share reveal during anonymous enumeration?
  • Why should you test anonymous access before providing credentials?
  • How does Enum4Linux extract user accounts from Windows systems?
  • What information does the password policy output provide for attack planning?
  • Frequently Asked Questions

    What is SMB enumeration?

    SMB enumeration discovers information about Windows/Samba systems through the SMB protocol, including shares, users, groups, password policies, and network resources. It's critical for Windows environment assessments.

    What ports does SMB use?

    SMB uses port 139 (NetBIOS Session Service) for older systems and port 445 (Direct Host SMB) for modern Windows. Port 445 provides direct TCP connectivity without NetBIOS overhead.

    What is the difference between null session and authenticated enumeration?

    Null session enumeration connects without credentials (anonymous access). Authenticated enumeration uses valid credentials for more complete results. Always try anonymous access first.

    What information can Enum4Linux extract?

    Enum4Linux extracts users (`-U`), shares (`-S`), groups (`-G`), password policies (`-P`), and system information. Use `-a` for full enumeration of all categories.

    How do you test share access with SMBClient?

    List shares anonymously: `smbclient -L //target -N`. Connect to a share: `smbclient //target/share -U user%pass`. Browse contents with `ls`, `cd`, and `get` commands.

    What is CrackMapExec used for?

    CrackMapExec automates SMB enumeration across large networks. Use `crackmapexec smb subnet -u user -p pass --shares` to enumerate shares on all hosts simultaneously.

    What does NT_STATUS_ACCESS_DENIED mean?

    This means the share exists but requires authentication. The share is accessible but you need valid credentials. Try common credentials or continue enumeration for other accessible shares.

    How do you enumerate SMB on a large network?

    First identify SMB hosts with `nmap -p 139,445 subnet`. Then run Enum4Linux or CrackMapExec on discovered hosts. Use NBTScan for quick NetBIOS name resolution across subnets.