Enumeration

Enumerating RDP establishes what you are attacking and how it is configured. The service leaks useful identity data, notably the hostname, domain, and OS build through the NTLM security provider during the connection handshake, and its security settings decide the attack: whether Network Level Authentication (NLA) is required (which forces credentials before a session), the negotiated security and encryption level, and the TLS certificate (which names the host and dates the system). This drives the choice between brute force, exposure analysis, and pre-auth exploitation.

bash
nmap -p3389 --script rdp-ntlm-info <target>    # hostname, domain, OS build via NTLM
nmap -p3389 --script rdp-enum-encryption <target>   # security layer and encryption level

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more