Enumerating RDP establishes what you are attacking and how it is configured. The service leaks useful identity data, notably the hostname, domain, and OS build through the NTLM security provider during the connection handshake, and its security settings decide the attack: whether Network Level Authentication (NLA) is required (which forces credentials before a session), the negotiated security and encryption level, and the TLS certificate (which names the host and dates the system). This drives the choice between brute force, exposure analysis, and pre-auth exploitation.
nmap -p3389 --script rdp-ntlm-info <target> # hostname, domain, OS build via NTLM
nmap -p3389 --script rdp-enum-encryption <target> # security layer and encryption level
Subtopics#
- Banner grabbing: version and identity disclosure.
- Security settings: NLA, encryption level, and certificate posture.