Windows Reconnaissance Basics: Network Discovery and Enumeration
Learn the fundamentals of Windows network reconnaissance including host discovery, port scanning, NetBIOS enumeration, and Active Directory mapping using Kali Linux tools.
The Foundation of Every Windows Security Assessment
Windows reconnaissance is the systematic process of gathering information about Windows-based systems and networks during security assessments. It covers discovering live hosts, identifying open ports, enumerating services, extracting user accounts, mapping network shares, and understanding Active Directory structure.
Every successful penetration test, security audit, and red team exercise begins with reconnaissance. Without it, you are operating blind. Understanding Windows-specific protocols like SMB, RDP, WinRM, and LDAP — and the tools that interrogate them — is the first skill every Windows security practitioner must master.
Prerequisites
Phase 1: Network Discovery
The first step is identifying live hosts on the network:
# ARP-based host discovery
netdiscover -r 192.168.1.0/24
# Nmap ping sweep
nmap -sn 192.168.1.0/24
# Fast host discovery with Nmap
nmap -sP 192.168.1.0/24
ARP discovery is preferred for local networks because it is fast, reliable, and cannot be blocked by host-based firewalls. For remote networks, use Nmap's ping sweep with ICMP and TCP probes.
Phase 2: Port and Service Scanning
Once live hosts are identified, scan for open ports:
# Scan common Windows ports
nmap -p 139,445,3389,5985,389,636 192.168.1.0/24
# Full port scan on discovered hosts
nmap -sV -sC -p- 192.168.1.10
# Detect SMB version
nmap -p 445 --script smb-os-discovery,smb-enum-shares 192.168.1.10
# Service version detection
nmap -sV --version-intensity 5 192.168.1.10
Key ports to look for:
| Port | Service | Purpose |
|------|---------|---------|
| 139 | NetBIOS Session | Legacy SMB name resolution |
| 445 | Direct SMB | Modern file sharing |
| 3389 | RDP | Remote Desktop access |
| 5985 | WinRM HTTP | Remote management |
| 5986 | WinRM HTTPS | Secure remote management |
| 389 | LDAP | Directory services |
| 636 | LDAPS | Secure directory services |
Phase 3: NetBIOS Enumeration
NetBIOS provides hostnames, workgroups, and domain information:
# Quick NetBIOS scan
nbtscan 192.168.1.0/24
# Nmap NetBIOS scripts
nmap --script nbstat 192.168.1.10
# Enum4Linux NetBIOS enumeration
enum4linux -n 192.168.1.10
The NetBIOS name reveals the hostname, workgroup or domain membership, and the server role (standalone, member server, or domain controller).
Phase 4: SMB Enumeration
Deep SMB enumeration extracts users, shares, and policies:
# Full SMB enumeration
enum4linux -a 192.168.1.10
# List shares
smbclient -L //192.168.1.10 -N
# Nmap SMB scripts
nmap --script smb-enum-shares,smb-enum-users -p 445 192.168.1.10
Focus on: accessible shares (especially writable ones), valid usernames for brute-force, weak password policies, and domain information.
Phase 5: User Enumeration
Extract user accounts for credential attacks:
# Enum4Linux user enumeration
enum4linux -U 192.168.1.10
# RID cycling for hidden users
enum4linux -a 192.168.1.10 | grep "User"
# CrackMapExec user enumeration
crackmapexec smb 192.168.1.0/24 -u '' -p '' --users
Windows reserves specific RIDs: 500 (Administrator), 501 (Guest), 502 (krbtgt). Custom accounts start at RID 1000+.
Phase 6: Active Directory Reconnaissance
For domain-joined environments:
# Domain enumeration with Enum4Linux
enum4linux -a -u admin -p password 192.168.1.10
# LDAP enumeration
ldapsearch -x -H ldap://192.168.1.10 -b "DC=domain,DC=com" -D "admin@domain.com" -w password
# Kerberoasting
impacket-GetUserSPNs domain.com/admin:password -dc-ip 192.168.1.10 -request
AD reconnaissance identifies domain controllers, user accounts, group memberships, trust relationships, and Group Policy configurations.
Phase 7: Documenting Findings
Record all discovered information:
Common Mistakes
Best Practices
Related Tools
Related Articles
Learning Roadmap
Summary
Windows reconnaissance is a systematic process of discovering and mapping network resources. Starting from host discovery and progressing through port scanning, NetBIOS enumeration, SMB analysis, and Active Directory mapping, each phase builds on the previous one. Always follow the methodology: discover → scan → enumerate → verify → document.