> For the complete documentation index, see [llms.txt](https://strange-1.gitbook.io/notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://strange-1.gitbook.io/notes/active-directory/password-spraying/making-a-target-user-list.md).

# Making a Target User list

### **SMB NULL Session to Pull User List**

```bash
# Using enum4linux
enum4linux -U ip  | grep "user:" | cut -f2 -d"[" | cut -f1 -d"]"

# Using rpcclient
rpcclient -U "" -N ip

# Using CrackMapExec --users Flag
crackmapexec smb ip --users
```

### **Gathering Users with LDAP Anonymous**

```bash
# Using ldapsearch
ldapsearch -h ip -x -b "DC=DOMAIN,DC=LOCAL" -s sub "(&(objectclass=user))"  | grep sAMAccountName: | cut -f2 -d" "

# Using windapsearch
./windapsearch.py --dc-ip ip -u "" -U
```

### **Enumerating Users with Kerbrute**

```bash
# Kerbrute User Enumeration
kerbrute userenum -d domain.local --dc ip /opt/jsmith.txt
```

### User Enumeration with Valid Credentials

```bash
# Using CrackMapExec with Valid Credentials
sudo crackmapexec smb ip -u eren -p pass --users
```
