> For the complete documentation index, see [llms.txt](https://cajac.gitbook.io/ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cajac.gitbook.io/ctf-notes/enum/smb-discovery/nmap-smb-nse-scripts.md).

# Nmap SMB NSE Scripts

The NSE scripts are located in the /usr/share/nmap/scripts directory.

## Discovery scripts

To run all discovery scripts on the SMB ports

```bash
nmap -v -p 139,445 --script "discovery and smb*" $TARGET_IP
```

## Full Enumeration

To run all SMB-related enumeration scripts in `nmap`

```bash
nmap -v -p 139,445 --script smb-*enum* $TARGET_IP
```

Available scripts are:

* [smb-enum-domains](https://nmap.org/nsedoc/scripts/smb-enum-domains.html)
* [smb-enum-groups](https://nmap.org/nsedoc/scripts/smb-enum-groups.html)
* [smb-enum-processes](https://nmap.org/nsedoc/scripts/smb-enum-processes.html)
* [smb-enum-services](https://nmap.org/nsedoc/scripts/smb-enum-services.html)
* [smb-enum-sessions](https://nmap.org/nsedoc/scripts/smb-enum-sessions.html)
* [smb-enum-shares](https://nmap.org/nsedoc/scripts/smb-enum-shares.html)
* [smb-enum-users](https://nmap.org/nsedoc/scripts/smb-enum-users.html)
* [smb-mbenum](https://nmap.org/nsedoc/scripts/smb-mbenum.html)

## List Shares <a href="#references" id="references"></a>

Attempts to list shares using the `srvsvc.NetShareEnumAll` MSRPC function, with the script [smb-enum-shares](https://nmap.org/nsedoc/scripts/smb-enum-shares.html)

```bash
nmap -v -p 139,445 --script smb-enum-shares $TARGET_IP
```

## OS Discovery <a href="#references" id="references"></a>

Run OS discovery, i.e. the script [smb-os-discovery](https://nmap.org/nsedoc/scripts/smb-os-discovery.html)

```bash
nmap -v -p 139,445 --script smb-os-discovery $TARGET_IP
```

## List of SMB scripts <a href="#references" id="references"></a>

### Information Gathering

<table><thead><tr><th width="182">Script</th><th>Description</th></tr></thead><tbody><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-domains.html">smb-enum-domains</a></td><td>Attempts to enumerate domains on a system, along with their policies. This generally requires credentials, except against Windows 2000. In addition to the actual domain, the "Builtin" domain is generally displayed. Windows returns this in the list of domains, but its policies don't appear to be used anywhere.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-groups.html">smb-enum-groups</a></td><td>Obtains a list of groups from the remote Windows system, as well as a list of the group's users. This works similarly to <code>enum.exe</code> with the <code>/G</code> switch.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-processes.html">smb-enum-processes</a></td><td>Pulls a list of processes from the remote server over SMB. This will determine all running processes, their process IDs, and their parent processes. It is done by querying the remote registry service, which is disabled by default on Vista; on all other Windows versions, it requires Administrator privileges.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-services.html">smb-enum-services</a></td><td>Retrieves the list of services running on a remote Windows system. Each service attribute contains service name, display name and service status of each service.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-sessions.html">smb-enum-sessions</a></td><td>Enumerates the users logged into a system either locally or through an SMB share. The local users can be logged on either physically on the machine, or through a terminal services session. Connections to a SMB share are, for example, people connected to fileshares or making RPC calls. Nmap's connection will also show up, and is generally identified by the one that connected "0 seconds ago".</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-shares.html">smb-enum-shares</a></td><td>Attempts to list shares using the <code>srvsvc.NetShareEnumAll</code> MSRPC function and retrieve more information about them using <code>srvsvc.NetShareGetInfo</code>. If access to those functions is denied, a list of common share names are checked.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-enum-users.html">smb-enum-users</a></td><td>Attempts to enumerate the users on a remote Windows system, with as much information as possible, through two different techniques (both over MSRPC, which uses port 445 or 139; see <code>smb.lua</code>). The goal of this script is to discover all user accounts that exist on a remote system. This can be helpful for administration, by seeing who has an account on a server, or for penetration testing or network footprinting, by determining which accounts exist on a system.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-ls.html">smb-ls</a></td><td>Attempts to retrieve useful information about files shared on SMB volumes. The output is intended to resemble the output of the UNIX <code>ls</code> command.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-mbenum.html">smb-mbenum</a></td><td>Queries information managed by the Windows Master Browser.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-os-discovery.html">smb-os-discovery</a></td><td>Attempts to determine the operating system, computer name, domain, workgroup, and current time over the SMB protocol (ports 445 or 139). This is done by starting a session with the anonymous account (or with a proper user account, if one is given; it likely doesn't make a difference); in response to a session starting, the server will send back all this information.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-protocols.html">smb-protocols</a></td><td>Attempts to list the supported protocols and dialects of a SMB server.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-security-mode.html">smb-security-mode</a></td><td>Returns information about the SMB security level determined by SMB.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-server-stats.html">smb-server-stats</a></td><td>Attempts to grab the server's statistics over SMB and MSRPC, which uses TCP ports 445 or 139.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-system-info.html">smb-system-info</a></td><td>Pulls back information about the remote system from the registry. Getting all of the information requires an administrative account, although a user account will still get a lot of it. Guest probably won't get any, nor will anonymous. This goes for all operating systems, including Windows 2000.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb2-capabilities.html">smb2-capabilities</a></td><td>Attempts to list the supported capabilities in a SMBv2 server for each enabled dialect.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb2-security-mode.html">smb2-security-mode</a></td><td>Determines the message signing configuration in SMBv2 servers for all supported dialects.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb2-time.html">smb2-time</a></td><td>Attempts to obtain the current system date and the start date of a SMB2 server.</td></tr></tbody></table>

### Vulnerability scanning <a href="#references" id="references"></a>

<table><thead><tr><th width="194">Script</th><th>Description</th></tr></thead><tbody><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-cve-2017-7494.html">smb-vuln-cve-2017-7494</a></td><td>Checks if target machines are vulnerable to the arbitrary shared library load vulnerability CVE-2017-7494.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-cve2009-3103.html">smb-vuln-cve2009-3103</a></td><td>Detects Microsoft Windows systems vulnerable to denial of service (CVE-2009-3103). This script will crash the service if it is vulnerable.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms06-025.html">smb-vuln-ms06-025</a></td><td>Detects Microsoft Windows systems with Ras RPC service vulnerable to MS06-025.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms07-029.html">smb-vuln-ms07-029</a></td><td>Detects Microsoft Windows systems with Dns Server RPC vulnerable to MS07-029.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms08-067.html">smb-vuln-ms08-067</a></td><td>Detects Microsoft Windows systems vulnerable to the remote code execution vulnerability known as MS08-067. This check is dangerous and it may crash systems.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms10-054.html">smb-vuln-ms10-054</a></td><td>Tests whether target machines are vulnerable to the ms10-054 SMB remote memory corruption vulnerability.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms10-061.html">smb-vuln-ms10-061</a></td><td>Tests whether target machines are vulnerable to ms10-061 Printer Spooler impersonation vulnerability.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-ms17-010.html">smb-vuln-ms17-010</a></td><td>Attempts to detect if a Microsoft SMBv1 server is vulnerable to a remote code execution vulnerability (ms17-010, a.k.a. EternalBlue). The vulnerability is actively exploited by WannaCry and Petya ransomware and other malware.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-regsvc-dos.html">smb-vuln-regsvc-dos</a></td><td>Checks if a Microsoft Windows 2000 system is vulnerable to a crash in regsvc caused by a null pointer dereference. This check will crash the service if it is vulnerable and requires a guest account or higher to work.</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb-vuln-webexec.html">smb-vuln-webexec</a></td><td>A critical remote code execution vulnerability exists in WebExService (WebExec).</td></tr><tr><td><a href="https://nmap.org/nsedoc/scripts/smb2-vuln-uptime.html">smb2-vuln-uptime</a></td><td>Attempts to detect missing patches in Windows systems by checking the uptime returned during the SMB2 protocol negotiation.</td></tr></tbody></table>

## Script Help <a href="#references" id="references"></a>

You can get help about a specific NSE script with

```bash
nmap --script-help smb-enum-users
```

To get help about several scripts you can use wildcards such as

```bash
nmap --script-help smb-enum-*
```

Or you can get help about all scripts in a specific category

```bash
nmap --script-help discovery
```

## Usage information <a href="#references" id="references"></a>

<details>

<summary>nmap --help</summary>

```bash
┌──(kali㉿kali)-[~/OffSec_Cources]
└─$ nmap --help                                                                                                                                                               
Nmap 7.94SVN ( https://nmap.org )
Usage: nmap [Scan Type(s)] [Options] {target specification}
TARGET SPECIFICATION:
  Can pass hostnames, IP addresses, networks, etc.
  Ex: scanme.nmap.org, microsoft.com/24, 192.168.0.1; 10.0.0-255.1-254
  -iL <inputfilename>: Input from list of hosts/networks
  -iR <num hosts>: Choose random targets
  --exclude <host1[,host2][,host3],...>: Exclude hosts/networks
  --excludefile <exclude_file>: Exclude list from file
HOST DISCOVERY:
  -sL: List Scan - simply list targets to scan
  -sn: Ping Scan - disable port scan
  -Pn: Treat all hosts as online -- skip host discovery
  -PS/PA/PU/PY[portlist]: TCP SYN/ACK, UDP or SCTP discovery to given ports
  -PE/PP/PM: ICMP echo, timestamp, and netmask request discovery probes
  -PO[protocol list]: IP Protocol Ping
  -n/-R: Never do DNS resolution/Always resolve [default: sometimes]
  --dns-servers <serv1[,serv2],...>: Specify custom DNS servers
  --system-dns: Use OS's DNS resolver
  --traceroute: Trace hop path to each host
SCAN TECHNIQUES:
  -sS/sT/sA/sW/sM: TCP SYN/Connect()/ACK/Window/Maimon scans
  -sU: UDP Scan
  -sN/sF/sX: TCP Null, FIN, and Xmas scans
  --scanflags <flags>: Customize TCP scan flags
  -sI <zombie host[:probeport]>: Idle scan
  -sY/sZ: SCTP INIT/COOKIE-ECHO scans
  -sO: IP protocol scan
  -b <FTP relay host>: FTP bounce scan
PORT SPECIFICATION AND SCAN ORDER:
  -p <port ranges>: Only scan specified ports
    Ex: -p22; -p1-65535; -p U:53,111,137,T:21-25,80,139,8080,S:9
  --exclude-ports <port ranges>: Exclude the specified ports from scanning
  -F: Fast mode - Scan fewer ports than the default scan
  -r: Scan ports sequentially - don't randomize
  --top-ports <number>: Scan <number> most common ports
  --port-ratio <ratio>: Scan ports more common than <ratio>
SERVICE/VERSION DETECTION:
  -sV: Probe open ports to determine service/version info
  --version-intensity <level>: Set from 0 (light) to 9 (try all probes)
  --version-light: Limit to most likely probes (intensity 2)
  --version-all: Try every single probe (intensity 9)
  --version-trace: Show detailed version scan activity (for debugging)
SCRIPT SCAN:
  -sC: equivalent to --script=default
  --script=<Lua scripts>: <Lua scripts> is a comma separated list of
           directories, script-files or script-categories
  --script-args=<n1=v1,[n2=v2,...]>: provide arguments to scripts
  --script-args-file=filename: provide NSE script args in a file
  --script-trace: Show all data sent and received
  --script-updatedb: Update the script database.
  --script-help=<Lua scripts>: Show help about scripts.
           <Lua scripts> is a comma-separated list of script-files or
           script-categories.
OS DETECTION:
  -O: Enable OS detection
  --osscan-limit: Limit OS detection to promising targets
  --osscan-guess: Guess OS more aggressively
TIMING AND PERFORMANCE:
  Options which take <time> are in seconds, or append 'ms' (milliseconds),
  's' (seconds), 'm' (minutes), or 'h' (hours) to the value (e.g. 30m).
  -T<0-5>: Set timing template (higher is faster)
  --min-hostgroup/max-hostgroup <size>: Parallel host scan group sizes
  --min-parallelism/max-parallelism <numprobes>: Probe parallelization
  --min-rtt-timeout/max-rtt-timeout/initial-rtt-timeout <time>: Specifies
      probe round trip time.
  --max-retries <tries>: Caps number of port scan probe retransmissions.
  --host-timeout <time>: Give up on target after this long
  --scan-delay/--max-scan-delay <time>: Adjust delay between probes
  --min-rate <number>: Send packets no slower than <number> per second
  --max-rate <number>: Send packets no faster than <number> per second
FIREWALL/IDS EVASION AND SPOOFING:
  -f; --mtu <val>: fragment packets (optionally w/given MTU)
  -D <decoy1,decoy2[,ME],...>: Cloak a scan with decoys
  -S <IP_Address>: Spoof source address
  -e <iface>: Use specified interface
  -g/--source-port <portnum>: Use given port number
  --proxies <url1,[url2],...>: Relay connections through HTTP/SOCKS4 proxies
  --data <hex string>: Append a custom payload to sent packets
  --data-string <string>: Append a custom ASCII string to sent packets
  --data-length <num>: Append random data to sent packets
  --ip-options <options>: Send packets with specified ip options
  --ttl <val>: Set IP time-to-live field
  --spoof-mac <mac address/prefix/vendor name>: Spoof your MAC address
  --badsum: Send packets with a bogus TCP/UDP/SCTP checksum
OUTPUT:
  -oN/-oX/-oS/-oG <file>: Output scan in normal, XML, s|<rIpt kIddi3,
     and Grepable format, respectively, to the given filename.
  -oA <basename>: Output in the three major formats at once
  -v: Increase verbosity level (use -vv or more for greater effect)
  -d: Increase debugging level (use -dd or more for greater effect)
  --reason: Display the reason a port is in a particular state
  --open: Only show open (or possibly open) ports
  --packet-trace: Show all packets sent and received
  --iflist: Print host interfaces and routes (for debugging)
  --append-output: Append to rather than clobber specified output files
  --resume <filename>: Resume an aborted scan
  --noninteractive: Disable runtime interactions via keyboard
  --stylesheet <path/URL>: XSL stylesheet to transform XML output to HTML
  --webxml: Reference stylesheet from Nmap.Org for more portable XML
  --no-stylesheet: Prevent associating of XSL stylesheet w/XML output
MISC:
  -6: Enable IPv6 scanning
  -A: Enable OS detection, version detection, script scanning, and traceroute
  --datadir <dirname>: Specify custom Nmap data file location
  --send-eth/--send-ip: Send using raw ethernet frames or IP packets
  --privileged: Assume that the user is fully privileged
  --unprivileged: Assume the user lacks raw socket privileges
  -V: Print version number
  -h: Print this help summary page.
EXAMPLES:
  nmap -v -A scanme.nmap.org
  nmap -v -sn 192.168.0.0/16 10.0.0.0/8
  nmap -v -iR 10000 -Pn -p 80
SEE THE MAN PAGE (https://nmap.org/book/man.html) FOR MORE OPTIONS AND EXAMPLES

```

</details>

## Resources <a href="#references" id="references"></a>

NSEDoc Reference Portal: <https://nmap.org/nsedoc/index.html>

NSE Categories: <https://nmap.org/nsedoc/categories/>

NSE Scripts: <https://nmap.org/nsedoc/scripts/>
