> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/fr/active-directory/enumeration/remote-sam-enumeration.md).

# Énumération SAM distante

### Principe

SAM signifie **Gestionnaire des comptes de sécurité**.

Il contient des informations sur :

* les comptes locaux ;
* les groupes locaux ;
* les appartenances aux groupes locaux.

Sur les anciennes versions de Windows, avant Windows 10 et Windows Server 2016, il était souvent possible d’énumérer certaines informations SAM à distance sans privilèges élevés.

### Énumérer les groupes locaux d’une machine distante

Avec PowerView :

```powershell
Get-NetLocalGroup -ComputerName WS02
```

Cette commande tente de récupérer les groupes locaux présents sur `WS02`.

### Alternative sans PowerView

Avec PowerShell Remoting :

```powershell
Invoke-Command -ScriptBlock { Get-LocalGroupMember -Group Administrators } -ComputerName WS02
```

Cette commande exécute `Get-LocalGroupMember` directement sur `WS02`.

Cela nécessite généralement que :

* PowerShell Remoting soit activé ;
* l’utilisateur dispose des droits nécessaires ;
* les règles réseau et de pare-feu l’autorisent.

### Voir les utilisateurs connectés à une machine distante

Avec PowerView :

```powershell
Get-NetLoggedon
```

Cette commande identifie les utilisateurs actuellement authentifiés sur une machine.

Il est utile de savoir :

* où un utilisateur est connecté ;
* si un administrateur est actif sur une machine ;
* quelles machines peuvent présenter un intérêt pour une analyse plus approfondie.

### Voir les sessions ouvertes vers votre machine

Avec PowerView :

```powershell
Get-NetSession
```

Cette commande affiche les sessions SMB établies sur la machine.

Par exemple, si un utilisateur tente d’accéder à :

```bash
//WS01/c$
```

<figure><img src="/files/fee268abe7e98d2620714038cdc826f632e7423a" alt=""><figcaption></figcaption></figure>

La connexion peut alors apparaître dans les sessions visibles.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/fr/active-directory/enumeration/remote-sam-enumeration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
