GO KALI FREE
BeginnerGuides

Windows Reconnaissance Basics: Network Discovery and Enumeration

Learn the fundamentals of Windows network reconnaissance including host discovery, port scanning, NetBIOS enumeration, and Active Directory mapping using Kali Linux tools.

#windows#reconnaissance#network scanning#enumeration#penetration testing#active directory

The Foundation of Every Windows Security Assessment

Windows reconnaissance is the systematic process of gathering information about Windows-based systems and networks during security assessments. It covers discovering live hosts, identifying open ports, enumerating services, extracting user accounts, mapping network shares, and understanding Active Directory structure.

Every successful penetration test, security audit, and red team exercise begins with reconnaissance. Without it, you are operating blind. Understanding Windows-specific protocols like SMB, RDP, WinRM, and LDAP — and the tools that interrogate them — is the first skill every Windows security practitioner must master.

Prerequisites

  • Kali Linux or similar penetration testing distribution
  • Basic understanding of TCP/IP networking
  • Knowledge of Windows operating systems
  • Network access to the target environment
  • Explicit written authorization to test the target
  • Phase 1: Network Discovery

    The first step is identifying live hosts on the network:

    # ARP-based host discovery
    netdiscover -r 192.168.1.0/24
    
    # Nmap ping sweep
    nmap -sn 192.168.1.0/24
    
    # Fast host discovery with Nmap
    nmap -sP 192.168.1.0/24
    

    ARP discovery is preferred for local networks because it is fast, reliable, and cannot be blocked by host-based firewalls. For remote networks, use Nmap's ping sweep with ICMP and TCP probes.

    Phase 2: Port and Service Scanning

    Once live hosts are identified, scan for open ports:

    # Scan common Windows ports
    nmap -p 139,445,3389,5985,389,636 192.168.1.0/24
    
    # Full port scan on discovered hosts
    nmap -sV -sC -p- 192.168.1.10
    
    # Detect SMB version
    nmap -p 445 --script smb-os-discovery,smb-enum-shares 192.168.1.10
    
    # Service version detection
    nmap -sV --version-intensity 5 192.168.1.10
    

    Key ports to look for:

    | Port | Service | Purpose |

    |------|---------|---------|

    | 139 | NetBIOS Session | Legacy SMB name resolution |

    | 445 | Direct SMB | Modern file sharing |

    | 3389 | RDP | Remote Desktop access |

    | 5985 | WinRM HTTP | Remote management |

    | 5986 | WinRM HTTPS | Secure remote management |

    | 389 | LDAP | Directory services |

    | 636 | LDAPS | Secure directory services |

    Phase 3: NetBIOS Enumeration

    NetBIOS provides hostnames, workgroups, and domain information:

    # Quick NetBIOS scan
    nbtscan 192.168.1.0/24
    
    # Nmap NetBIOS scripts
    nmap --script nbstat 192.168.1.10
    
    # Enum4Linux NetBIOS enumeration
    enum4linux -n 192.168.1.10
    

    The NetBIOS name reveals the hostname, workgroup or domain membership, and the server role (standalone, member server, or domain controller).

    Phase 4: SMB Enumeration

    Deep SMB enumeration extracts users, shares, and policies:

    # Full SMB enumeration
    enum4linux -a 192.168.1.10
    
    # List shares
    smbclient -L //192.168.1.10 -N
    
    # Nmap SMB scripts
    nmap --script smb-enum-shares,smb-enum-users -p 445 192.168.1.10
    

    Focus on: accessible shares (especially writable ones), valid usernames for brute-force, weak password policies, and domain information.

    Phase 5: User Enumeration

    Extract user accounts for credential attacks:

    # Enum4Linux user enumeration
    enum4linux -U 192.168.1.10
    
    # RID cycling for hidden users
    enum4linux -a 192.168.1.10 | grep "User"
    
    # CrackMapExec user enumeration
    crackmapexec smb 192.168.1.0/24 -u '' -p '' --users
    

    Windows reserves specific RIDs: 500 (Administrator), 501 (Guest), 502 (krbtgt). Custom accounts start at RID 1000+.

    Phase 6: Active Directory Reconnaissance

    For domain-joined environments:

    # Domain enumeration with Enum4Linux
    enum4linux -a -u admin -p password 192.168.1.10
    
    # LDAP enumeration
    ldapsearch -x -H ldap://192.168.1.10 -b "DC=domain,DC=com" -D "admin@domain.com" -w password
    
    # Kerberoasting
    impacket-GetUserSPNs domain.com/admin:password -dc-ip 192.168.1.10 -request
    

    AD reconnaissance identifies domain controllers, user accounts, group memberships, trust relationships, and Group Policy configurations.

    Phase 7: Documenting Findings

    Record all discovered information:

  • Host inventory with IP addresses, hostnames, and operating systems
  • Open ports and running services for each host
  • User accounts and their privilege levels
  • Accessible shares and their permission settings
  • Password policies and account lockout configurations
  • Domain structure and trust relationships
  • Common Mistakes

  • Scanning without authorization (illegal under CFAA and similar laws)
  • Running aggressive scans against production systems causing service disruption
  • Ignoring non-standard ports where services may be running
  • Not saving scan results for later analysis
  • Skipping passive discovery before active scanning
  • Best Practices

  • Start passive, escalate to active scanning gradually
  • Save all results in multiple formats (-oA for Nmap, -o for Enum4Linux)
  • Verify findings with multiple tools before reporting
  • Respect rate limits and account lockout policies
  • Document everything for the final security assessment report
  • Related Tools

  • [Nmap](/tools/nmap) — Port scanning and service detection
  • [Netdiscover](/tools/netdiscover) — ARP-based host discovery
  • [NBTScan](/tools/nbtscan) — Fast NetBIOS scanning
  • [Enum4Linux](/tools/enum4linux) — Comprehensive SMB enumeration
  • [SMBClient](/tools/smbclient) — Interactive share access
  • [CrackMapExec](/tools/crackmapexec) — Large-scale network attacks
  • [NetExec](/tools/netexec) — Modern post-exploitation toolkit
  • Related Articles

  • [SMB Enumeration Complete Guide](/learn/smb-enumeration-complete-guide) — Beginner to advanced SMB workflow
  • [SMB Enumeration Guide](/learn/smb-enumeration-guide) — Deep SMB enumeration techniques
  • [Active Directory Fundamentals](/learn/active-directory-fundamentals) — AD security assessment
  • [Enum4Linux Guide](/learn/enum4linux-guide) — Enum4Linux tutorial
  • Learning Roadmap

  • Master [Nmap](/tools/nmap) for port scanning and service detection
  • Learn [Netdiscover](/tools/netdiscover) for ARP-based host discovery
  • Use [NBTScan](/tools/nbtscan) for quick NetBIOS name resolution
  • Run [Enum4Linux](/tools/enum4linux) for comprehensive SMB enumeration
  • Test shares with [SMBClient](/tools/smbclient) for interactive access
  • Scale operations with [CrackMapExec](/tools/crackmapexec) for network-wide attacks
  • Summary

    Windows reconnaissance is a systematic process of discovering and mapping network resources. Starting from host discovery and progressing through port scanning, NetBIOS enumeration, SMB analysis, and Active Directory mapping, each phase builds on the previous one. Always follow the methodology: discover → scan → enumerate → verify → document.

    Related SMB Tool Recommendations

  • [SMBClient](/tools/smbclient) — Verify share access and browse discovered SMB shares
  • [Enum4Linux](/tools/enum4linux) — Enumerate SMB users, groups, shares, and policies
  • [Enum4Linux-NG](/tools/enum4linux-ng) — Run modern SMB enumeration with structured output
  • [NBTScan](/tools/nbtscan) — Resolve NetBIOS names before deeper SMB testing
  • [CrackMapExec](/tools/crackmapexec) — Scale SMB enumeration across larger networks
  • [NetExec](/tools/netexec) — Use modern SMB and Active Directory automation
  • Knowledge Check

  • What are the two primary SMB ports and when is each used?
  • Why is ARP discovery preferred over ICMP for local networks?
  • What Windows user accounts have well-known RIDs?
  • How does NetBIOS enumeration complement SMB enumeration?
  • What is the difference between LDAP and LDAPS?
  • Frequently Asked Questions

    What is Windows reconnaissance?

    Windows reconnaissance gathers information about Windows systems and networks during security assessments, including host discovery, port scanning, service enumeration, user extraction, and Active Directory mapping.

    What ports should I scan on Windows systems?

    Essential ports: 139/445 (SMB), 3389 (RDP), 5985/5986 (WinRM), 389/636 (LDAP). These reveal file sharing, remote access, management, and directory services available on the target.

    How do you discover Windows hosts on a network?

    Use ARP-based discovery (`netdiscover -r subnet`) for local networks, or Nmap ping sweep (`nmap -sn subnet`). ARP is preferred as it's fast, reliable, and cannot be blocked by host firewalls.

    What is NetBIOS enumeration?

    NetBIOS enumeration extracts hostnames, workgroups, domain membership, and server roles. Use NBTScan (`nbtscan subnet`) for quick discovery or Enum4Linux for detailed enumeration.

    How do you enumerate SMB shares?

    Use `enum4linux -a target` for comprehensive enumeration or `smbclient -L //target -N` for anonymous share listing. Nmap NSE scripts (`smb-enum-shares`) also provide share information.

    How do you extract user accounts from Windows?

    Use `enum4linux -U target` for user enumeration, or `crackmapexec smb subnet -u '' -p '' --users` for network-wide enumeration. RID cycling reveals hidden accounts.

    What is the difference between SMB ports 139 and 445?

    Port 445 (Direct SMB) is used by modern Windows systems for direct TCP connectivity. Port 139 (NetBIOS Session) is used by older systems and Samba. Always check both ports.

    How do you enumerate Active Directory?

    Use LDAP enumeration with tools like ldapsearch, BloodHound for AD mapping, and CrackMapExec for domain-wide enumeration. Ensure you have proper authorization for AD testing.