> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/pt-br/active-directory/enumeration/impacket-and-rpcclient.md).

# Impacket e rpcclient

### Configuração local de DNS

Na máquina Linux, adicionamos as resoluções DNS em `/etc/hosts`:

{% code overflow="wrap" %}

```bash
172.16.0.10 WS01.whoami.local
172.16.0.20 WS02.whoami.local
172.16.0.100 DC01.whoami.local
```

{% endcode %}

Isso permite usar nomes de máquinas em vez de endereços IP.

### Enumeração com rpcclient

Conexão com um usuário de domínio:

{% code overflow="wrap" %}

```bash
rpcclient -U "whoami/user1" WS01.whoami.local
```

{% endcode %}

`rpcclient` pode consultar serviços específicos do RPC do Windows.

Ele pode ser usado para listar:

* usuários;
* grupos;
* algumas informações do SAM;
* certas informações de domínio, dependendo dos privilégios disponíveis.

<figure><img src="/files/538ff8f182c8976b57cc740a8ff0aa92888d901c" alt=""><figcaption></figcaption></figure>

### Enumeração com Impacket

#### dump de sincronização

{% code overflow="wrap" %}

```bash
samrdump.py 'whoami/user2'@WS02.whoami.local
```

{% endcode %}

`samrdump.py` permite listar informações do SAM acessíveis remotamente.

<figure><img src="/files/f7b1da22c274e2f7b5aba83cfbccdd9052576495" alt=""><figcaption></figcaption></figure>

#### secretsdump

{% code overflow="wrap" %}

```bash
secretsdump.py 'whoami/user2'@WS02.whoami.local
```

{% endcode %}

`secretsdump.py` é mais sensível: é usado para extrair segredos ou hashes quando o usuário tem os privilégios necessários.

Em um laboratório, você pode testar com um usuário com permissões elevadas.

### Monitore sessões com NetView

{% code overflow="wrap" %}

```bash
netview.py 'whoami/administrador' -target WS01.whoami.local
```

{% endcode %}

Este comando permite observar certas sessões ou conexões vinculadas a uma máquina alvo.

Então, podemos criar uma conexão SMB com a máquina:

{% code overflow="wrap" %}

```bash
dir //WS01/c$
```

{% endcode %}

Se uma sessão for estabelecida, ela pode ficar visível com as ferramentas de enumeração.

<figure><img src="/files/524c6347ffd276d9c761fbd94b0764f30f680f9f" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/pt-br/active-directory/enumeration/impacket-and-rpcclient.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
