Enumeration actively engages a system to query it for information — routing tables, users, groups, machine names, network resources — to discover and exploit vulnerabilities. This module covers Windows enumeration, NetBIOS, SNMP, LDAP, NTP, SMTP enumeration, and Active Directory attacks.
The CEHStudy app carries 6 flashcards for Module 4 in 1 section — open the Module 4 deck and pair every protocol with its enumeration command.
Key Topics Covered
Difference between enumeration and scanning/footprinting
Windows enumeration: shares, null sessions, user accounts
Security Identifier (SID) format and common RID values
NetBIOS enumeration techniques and tools
SNMP community strings, OIDs, MIBs, and enumeration commands
LDAP hierarchical structure and information extraction
NTP enumeration for network reconnaissance
SMTP user enumeration via VRFY, EXPN, RCPT TO commands
Active Directory brute force techniques
Important Terms & Concepts
Enumeration: Actively engaging a system to extract user accounts, passwords, hashes, SMB info, SNMP data, and directory service information.
Null session: An anonymous connection allowing enumeration of machine configuration: net use \\target\\ipc$ \"\" /user: \"\"
What is the most critical RID to identify? RID 500 — the Administrator account. It is the most powerful account on any Windows system.
How do you protect against SNMP enumeration? Change default community strings, use SNMPv3 with encryption, and restrict SNMP access to authorized managers only.
Enumeration directly queries target systems to extract usernames, machine names, network shares, group memberships, and other critical data — the active information-gathering step in the CEH v13 exam. Unlike scanning (which identifies open ports), it probes those services with protocol-specific commands to pull structured information. Module 4 covers Windows/SMB enumeration, NetBIOS name resolution, SNMP community string exploitation, LDAP directory traversal, NTP data extraction, and SMTP user validation. About 8% of CEH v13 exam questions come from Module 4.
Key Concepts in Enumeration
Windows Null Session Enumeration: Connecting to a target's IPC$ share without credentials (net use \\target\\ipc$ \"\" /user:\"\") exposes user accounts, group memberships, and machine names. enum4linux automates it; know what null sessions expose and how to disable them via registry or firewall rules.
SID and RID Identification: Windows Security Identifiers (SIDs) follow the format S-1-5-21--. RIDs identify specific accounts: 500 = local Administrator, 501 = Guest, 512 = Domain Admins, 513 = Domain Users — the values that flag privilege escalation targets.
SNMP Community Strings & OIDs: SNMP v1/v2 use plaintext community strings (default: public/read, private/write) that grant access to Management Information Bases (MIBs). Querying Object Identifiers (OIDs) can extract network topology, connected hosts, running services, and OS versions. SNMPv3 fixes this with authentication and encryption.
SMTP User Enumeration: VRFY asks a mail server to confirm a user exists; EXPN reveals mailing list members. Combined with RCPT TO, they can map an organization's email infrastructure. Modern servers often disable VRFY/EXPN — the exam still tests them.
Common Exam Mistakes in Module 4
Calling port scanning "enumeration": Scanning answers which ports are listening; enumeration interrogates those services to extract usernames, shares, groups and machine names. When a question asks which technique yields valid account names, it wants the protocol-level tool, not nmap.
Mis-assigning the enumeration ports: NetBIOS lives on 137 (Name Service), 138 (Datagram) and 139 (Session); SNMP on 161; LDAP on 389 unencrypted and 636 as LDAPS; SMTP on 25; SMB on 445. The exam pairs services with wrong ports — know each correct one.
Assuming VRFY/EXPN are blocked everywhere: VRFY confirms whether an address exists and EXPN expands mailing lists wherever left enabled — the exam tests the commands themselves. Same trap on SNMP: the default "public" community is read-only, leaking system info, interfaces, and routing tables but never passwords.
Tools Used in Enumeration
The protocol-by-protocol enumeration toolkit from the CEH exam:
enum4linux: wraps rpcclient, smbclient, and nmblookup for users, groups, shares, and policies on Windows/Active Directory hosts (SMB, NetBIOS)
nbtscan / nbtstat: NetBIOS name-table queries that return computer names, user names and workgroups from ports 137/139
rpcclient: direct Remote Procedure Call client for Windows account and group info at the protocol level
snmpwalk / snmpget: traverse the MIB tree with a community string — unchanged defaults (public/private) hand over system info, interface stats and routing tables
ldapsearch: issues LDAP queries to extract user lists, group memberships, and organizational structure (Active Directory over 389/636)
smtp-user-enum: automates the SMTP VRFY/EXPN/RCPT TO sequence to validate mailbox names against a wordlist
Swaks: the Swiss Army Knife for SMTP — crafts custom transactions for user enumeration and misconfiguration testing
Worked Example: Enumerating a Windows Host End to End
A ping sweep on an authorized internal range flags 10.20.30.4 as live. Ports 139, 161 and 445 are open — a Windows box with NetBIOS, SNMP and SMB all exposed.
Why that order matters: open a null session (net use \\10.20.30.4\\ipc$ with empty credentials), read the SID and note RIDs 500, 501, 512, and 513 (Administrator, Guest, Domain Admins, Domain Users); run enum4linux for users, groups, and shares; walk SNMP with the "public" community for uptime, interfaces, and routes. The output — real account names and share paths — is what the exploitation phase needs next.
How to Study Enumeration for the CEH v13 Exam
To study Module 4:
Memorize the common enumeration ports and their associated protocols (25/SMTP, 137/139/NetBIOS, 161/SNMP, 389/LDAP, 445/SMB)
Understand the SID format and memorize the critical RID values (500, 501, 512, 513, 518-519 for Domain Controllers)
Set up a Windows Server domain controller VM and an attacking Linux VM — practice null session enumeration (enum4linux), SNMP community discovery (snmpwalk), and LDAP queries (ldapsearch)
What is the difference between enumeration and scanning on the CEH exam?
Scanning (Module 3) identifies open ports and running services — "what is accessible?" Enumeration (Module 4) sends protocol-specific commands to those services to extract actual data — usernames, group memberships, machine names, network shares. Expect scenarios asking which is which, based on the level of detail gathered.
How does SNMP version 3 improve security over v1/v2?
SNMP v1/v2c use plaintext community strings — anyone who knows the string (often "public") can read or modify MIB data. SNMPv3 adds three security models: noAuthNoPriv (no authentication), authNoPriv (authentication, no encryption), and authPriv (authentication with AES/DES encryption), plus per-user credentials instead of shared community strings. Know v3 as the recommended secure implementation and all three levels.
Related CEH v13 Modules
Module 5: Vulnerability Analysis — enumerated OS versions, services, and accounts feed vulnerability assessment for specific CVEs
Module 6: System Hacking — enumerated usernames and RIDs target brute force, password cracking, and privilege escalation