SMB, SNMP, LDAP, RPC & NFS Enumeration Command Builder (2026)

Generate copy-ready Active Directory and network service enumeration commands for NetExec (CrackMapExec), smbclient, rpcclient, snmpwalk, ldapsearch, enum4linux-ng, and BloodHound.

SMB, SNMP, LDAP & NetBIOS Enumeration Command Matrix — Interactive Console
Runs locally in your browser • Instant output

SMB / NetBIOS / RPC Enumeration (Ports 139, 445)

smbclient
$ smbclient -U 'corp.local\svc_backup%Winter2026!' -L //10.10.11.152
rpcclient
$ rpcclient -U 'corp.local/svc_backup%Winter2026!' 10.10.11.152 -c "enumdomusers; enumdomgroups"
enum4linux-ng
$ enum4linux-ng -A -u 'svc_backup' -p 'Winter2026!' -d 'corp.local' 10.10.11.152
netexec smb
$ netexec smb 10.10.11.152 -d 'corp.local' -u 'svc_backup' -p 'Winter2026!' --shares --users --loggedon-users

SNMP MIB & OID Walking (UDP Port 161)

snmpwalk v2c (Full MIB Tree)
$ snmpwalk -v2c -c public 10.10.11.152 1.3.6.1.2.1
snmpwalk (Windows Users OID)
$ snmpwalk -v2c -c public 10.10.11.152 1.3.6.1.4.1.77.1.2.25
snmpwalk (Linux/Win Running Processes OID)
$ snmpwalk -v2c -c public 10.10.11.152 1.3.6.1.2.1.25.4.2.1.2
snmpwalk v3 (Authenticated SHA/AES)
$ snmpwalk -v3 -l authPriv -u 'svc_backup' -a SHA -A 'Winter2026!' -x AES -X 'Winter2026!' 10.10.11.152

Active Directory LDAP Enumeration (Ports 389, 636 | DC=corp,DC=local)

ldapsearch (Dump Users & SPNs)
$ ldapsearch -x -H ldap://10.10.11.152 -D "svc_backup@corp.local" -w 'Winter2026!' -b "DC=corp,DC=local" "(objectClass=user)" sAMAccountName servicePrincipalName memberOf
windapsearch (Privileged AD Objects)
$ windapsearch -d corp.local --dc-ip 10.10.11.152 -u 'svc_backup@corp.local' -p 'Winter2026!' -U --da --spn --unconstrained-users

NFS & SunRPC Portmapper Enumeration (Ports 111, 2049)

showmount -e (Exported NFS Shares)
$ showmount -e 10.10.11.152
rpcinfo (Registered RPC Programs)
$ rpcinfo -p 10.10.11.152
mount NFSv3 (Inspect no_root_squash)
$ sudo mkdir -p /mnt/nfs_audit && sudo mount -t nfs -o vers=3,nolock 10.10.11.152:/ /mnt/nfs_audit
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![SMB, SNMP, LDAP & NetBIOS Enumeration Command Matrix](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/smb-snmp-ldap-enumeration-builder/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/smb-snmp-ldap-enumeration-builder/">SMB, SNMP, LDAP & NetBIOS Enumeration Command Matrix — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: SMB, SNMP, LDAP & NetBIOS Enumeration Command Matrix

Quick Answer & 2026 Technical Summary (smb snmp ldap enumeration commands)Updated 2026 Standard

An SMB null session occurs when a client connects to the hidden inter-process communication share (\\target\IPC$) with an empty username and password (smbclient -N or rpcclient -U '' -N). If Windows RestrictAnonymous policies are misconfigured, attackers can query SAMR/LSARPC pipes to enumerate domain users, groups, RIDs, and password lockout policies without credentials. Use this interactive smb snmp ldap enumeration commands above to test netexec crackmapexec cheat sheet, active directory ldapsearch generator, and snmpwalk oid enumeration locally in your browser with zero server uploads.

Target Keyword Spec: smb snmp ldap enumeration commands | Modules: Protocol-by-Port Enumeration Matrix • Null Session vs Authenticated & Pass-the-Hash Modes • SNMP MIB OID & Community String Explorer
Primary Focus: smb snmp ldap enumeration commands
Core Capability: netexec crackmapexec cheat sheet
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Protocol-by-Port Enumeration Matrixnetexec crackmapexec cheat sheetDedicated command generators for SMB/CIFS (139/445), MSRPC (135), NetBIOS (...Internal Active Directory Penetration Testing
Null Session vs Authenticated & Pass-the-Hash Modesactive directory ldapsearch generatorSwitch seamlessly between anonymous/null-session probes (-U '' -N), domain ...CEH Module 04 & OSCP Active Directory Labs
SNMP MIB OID & Community String Explorersnmpwalk oid enumerationIncludes built-in OID presets for Windows running processes (1.3.6.1.2.1.25...Defensive Hardening & Null Session Verification
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

CEH Module 04: Network Enumeration Techniques & Countermeasures

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use SMB, SNMP, LDAP & NetBIOS Enumeration Command Matrix

01

Enter Target IP, Domain FQDN & Base DN

Specify your target host or Domain Controller IP (e.g., 10.10.11.100) and domain name (e.g., corp.local, which auto-generates DC=corp,DC=local).

02

Select Authentication Mode

Choose Anonymous/Null Session to test unauthenticated exposure, or supply a username and password/NTLM hash for post-foothold enumeration.

03

Pick Target Protocol (SMB, RPC, LDAP, SNMP, or NFS)

Browse categorized command cards showing the exact tool binary, flags, and expected security findings for that service.

04

Copy CLI Commands & Hardening Countermeasures

Click any command to copy it to your clipboard and review the corresponding remediation guidance for your audit report.

Key Capabilities & Technical Architecture

Protocol-by-Port Enumeration Matrix

Dedicated command generators for SMB/CIFS (139/445), MSRPC (135), NetBIOS (137), SNMP v1/v2c/v3 (161), Active Directory LDAP/LDAPS (389/636), and NFSv3/v4 (2049).

Null Session vs Authenticated & Pass-the-Hash Modes

Switch seamlessly between anonymous/null-session probes (-U '' -N), domain user credentials, and NTLM hash authentication (--hashes LM:NT) across NetExec and Impacket tools.

SNMP MIB OID & Community String Explorer

Includes built-in OID presets for Windows running processes (1.3.6.1.2.1.25.4.2.1.2), installed software, user accounts, and TCP routing tables using snmpwalk and onesixtyone.

Active Directory LDAP & Kerberos Attack Paths

Generate ldapsearch filters for SPN Kerberoasting (servicePrincipalName=*), AS-REP Roasting, unconstrained delegation, and RustHound/BloodHound-python ingestion.

Practical Use Cases

Internal Active Directory Penetration Testing

Enumerate readable SYSVOL/NETLOGON shares, password policies, domain trusts, and Kerberoastable service accounts from a single target DC IP and domain name.

CEH Module 04 & OSCP Active Directory Labs

Reference exact CLI syntax and port mappings for enum4linux-ng, rpcclient, smbmap, Impacket GetNPUsers/GetUserSPNs, and snmp-check.

Defensive Hardening & Null Session Verification

Verify that RestrictAnonymous, SMBv2/v3 signing requirements, LDAP channel binding, and non-default SNMPv3 authentication are enforced across enterprise hosts.

Frequently Asked Questions (FAQs)

What is an SMB or IPC$ Null Session and how does it work?+

An SMB null session occurs when a client connects to the hidden inter-process communication share (\\target\IPC$) with an empty username and password (smbclient -N or rpcclient -U '' -N). If Windows RestrictAnonymous policies are misconfigured, attackers can query SAMR/LSARPC pipes to enumerate domain users, groups, RIDs, and password lockout policies without credentials.

Why did NetExec (nxc) replace CrackMapExec (cme)?+

NetExec (nxc) is the actively maintained successor fork of CrackMapExec. It uses identical command-line flags (such as nxc smb <target> -u user -p pass --shares --users) while adding modern Impacket updates, LDAP bloodhound collection, and Kerberos authentication enhancements.

How does SNMP v1/v2c enumeration expose sensitive Windows and Linux host data?+

SNMP v1 and v2c authenticate solely via a cleartext community string (frequently left as 'public' for read-only or 'private' for read-write). By walking the Host Resources MIB tree (1.3.6.1.2.1.25), an auditor can extract local Windows usernames, running process command lines (sometimes containing cleartext passwords), and network interfaces.

How is the LDAP Base Distinguished Name (Base DN) formatted?+

An Active Directory domain name is split by its dots into Domain Component (DC) attributes. For example, the domain 'internal.corp.local' translates to the LDAP Base DN 'DC=internal,DC=corp,DC=local'.

How do organizations remediate SMB and LDAP enumeration risks?+

Disable SMBv1 completely, enforce SMB packet signing via Group Policy to prevent NTLM relay, disable anonymous SAM/share enumeration, enforce LDAP signing and LDAPS channel binding on Domain Controllers, and upgrade SNMPv2c to SNMPv3 with SHA-256 authentication and AES encryption.