cme IP -u '' -p '' --users
lookupsids DOMAIN/guest@$target
rpcclient -U “” $target
enumdomusers
ldapsearch -x -h $target -b base namingcontext
nmap -p 88 --script=krb5-enum-users --script-args="krb5-enum-users.realm='<domain>',userdb=<users_list_file>" <ip>
kerbrute userenum -d domain.name --dc $target usernamelist.txt
cme IP -u '' -p '' --pass-poll
# query users
windapsearch -m users --dc DCIP
# query login names
windapsearch -m users --attrs UserPrincipalName --dc DCIP | awk -F"Name:" '{print $2}' | awk '!/^$/'
# descriptions (often contain passwords)
windapsearch -m users --attrs Description --dc DCIP
# query all attributes for password
windapsearch -m users --full --dc DCIP | grep -i password