> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/es/active-directory/enumeration/impacket-and-rpcclient.md).

# Impacket y rpcclient

### Configuración local de DNS

En la máquina Linux, añadimos las resoluciones DNS en `/etc/hosts`:

{% code overflow="wrap" %}

```bash
172.16.0.10 WS01.whoami.local
172.16.0.20 WS02.whoami.local
172.16.0.100 DC01.whoami.local
```

{% endcode %}

Esto permite usar nombres de máquina en lugar de direcciones IP.

### Enumeración con rpcclient

Conexión con un usuario de dominio:

{% code overflow="wrap" %}

```bash
rpcclient -U "whoami/user1" WS01.whoami.local
```

{% endcode %}

`rpcclient` puede consultar servicios RPC específicos de Windows.

Se puede usar para listar:

* usuarios;
* grupos;
* cierta información de SAM;
* cierta información del dominio según los permisos disponibles.

<figure><img src="/files/3bf2751e9760dc50760ef0fea04111c5a23fdcd2" alt=""><figcaption></figcaption></figure>

### Enumeración con Impacket

#### volcado de sincronización

{% code overflow="wrap" %}

```bash
samrdump.py 'whoami/user2'@WS02.whoami.local
```

{% endcode %}

`samrdump.py` permite listar información de SAM accesible de forma remota.

<figure><img src="/files/6198dec0f86787a41bf232b683b0d0c6de6bbdf8" alt=""><figcaption></figcaption></figure>

#### secretsdump

{% code overflow="wrap" %}

```bash
secretsdump.py 'whoami/user2'@WS02.whoami.local
```

{% endcode %}

`secretsdump.py` es más sensible: se utiliza para extraer secretos o hashes cuando el usuario tiene los permisos necesarios.

En un laboratorio, puedes probar con un usuario con permisos elevados.

### Escuchar sesiones con NetView

{% code overflow="wrap" %}

```bash
netview.py 'whoami/administrador' -target WS01.whoami.local
```

{% endcode %}

Este comando permite observar ciertas sesiones o conexiones vinculadas a una máquina objetivo.

Luego, podemos crear una conexión SMB con la máquina:

{% code overflow="wrap" %}

```bash
dir //WS01/c$
```

{% endcode %}

Si se establece una sesión, puede ser visible con las herramientas de enumeración.

<figure><img src="/files/f1bfb71551ef630b1760fa68741fe54c2e27c28c" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/es/active-directory/enumeration/impacket-and-rpcclient.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
