Windows Enumeration Tools Roy
Introduction SMB Protocol Inter Process Communication(IPC)
Winfingerprint SMB, TCP, UDP, ICMP, RPC, and SNMP scans nfingerprint.php Ping Response NetBIOS Share Fingerprint NetBIOS Share Password Policy Running Services Users SID Groups Network Service Pack Session Disks Ports
GetUserInfo TCP port UserInfo.zip
Enum AZOR/Files/enum.tar.gz
PsTools Using NetBIOS port Services –NetLogon –Server –RemoteRegistry IPC$ share must be available
Psfile shows files opened remotely
PsLoggedon see who's logged on locally and via resource sharing FATCAT-E6GDFAFE CAT User:Administrator
PsGetSid mike
PsInfo Get information about local or remote windows system
PsService local and remote services viewer/controller
PsList List the Process information Open taskmgr.exe
PsKill kill processes by name or process ID
PsSuspend suspend or resume processes on a local or remote NT system.
PsLogList local and remote event log viewer System Security Application I->Information E->Errors W->Warning Audit Success Audit Failure Clean Log -> -c
PsExec executes a program on a remote system Access to the ADMIN$ share
PsShutdown Shutdown, logoff and power manage local and remote systems
Summary SMB