ALL PASS, NO FAIL!

CEH v13 Module 4: Enumeration

Enumeration actively engages a system to query it for information — routing tables, users, groups, machine names, network resources — to discover and exploit vulnerabilities. This module covers Windows enumeration, NetBIOS, SNMP, LDAP, NTP, SMTP enumeration, and Active Directory attacks.

The CEHStudy app carries 6 flashcards for Module 4 in 1 section — open the Module 4 deck and pair every protocol with its enumeration command.

Key Topics Covered

Important Terms & Concepts

Enumeration: Actively engaging a system to extract user accounts, passwords, hashes, SMB info, SNMP data, and directory service information.
Null session: An anonymous connection allowing enumeration of machine configuration: net use \\target\\ipc$ \"\" /user: \"\"
SID format: S---- — e.g., S-1-5-21-...-500 = Administrator
Common RIDs: 500 = Administrator, 501 = Guest, 512 = Domain Admins, 513 = Domain Users
NetBIOS: Network Basic Input/Output System — naming system for Windows machines enabling file/printer sharing via SMB.
SNMP community strings: Read (public) = read-only access. Write (private) = full configuration access.
LDAP: Lightweight Directory Access Protocol — hierarchical structure: domain > child-domains > OUs > users/groups/computers.
SMTP enumeration commands: VRFY validates email addresses. EXPN reveals mailing list members. RCPT TO defines recipients.

Common Enumeration Ports

How to Study This Module

Frequently Asked Questions

What is the most critical RID to identify?
RID 500 — the Administrator account. It is the most powerful account on any Windows system.

How do you protect against SNMP enumeration?
Change default community strings, use SNMPv3 with encryption, and restrict SNMP access to authorized managers only.

Related Modules

What is Enumeration in Ethical Hacking?

Enumeration directly queries target systems to extract usernames, machine names, network shares, group memberships, and other critical data — the active information-gathering step in the CEH v13 exam. Unlike scanning (which identifies open ports), it probes those services with protocol-specific commands to pull structured information. Module 4 covers Windows/SMB enumeration, NetBIOS name resolution, SNMP community string exploitation, LDAP directory traversal, NTP data extraction, and SMTP user validation. About 8% of CEH v13 exam questions come from Module 4.

Key Concepts in Enumeration

Common Exam Mistakes in Module 4

Calling port scanning "enumeration": Scanning answers which ports are listening; enumeration interrogates those services to extract usernames, shares, groups and machine names. When a question asks which technique yields valid account names, it wants the protocol-level tool, not nmap.
Mis-assigning the enumeration ports: NetBIOS lives on 137 (Name Service), 138 (Datagram) and 139 (Session); SNMP on 161; LDAP on 389 unencrypted and 636 as LDAPS; SMTP on 25; SMB on 445. The exam pairs services with wrong ports — know each correct one.
Assuming VRFY/EXPN are blocked everywhere: VRFY confirms whether an address exists and EXPN expands mailing lists wherever left enabled — the exam tests the commands themselves. Same trap on SNMP: the default "public" community is read-only, leaking system info, interfaces, and routing tables but never passwords.

Tools Used in Enumeration

The protocol-by-protocol enumeration toolkit from the CEH exam:

Worked Example: Enumerating a Windows Host End to End

A ping sweep on an authorized internal range flags 10.20.30.4 as live. Ports 139, 161 and 445 are open — a Windows box with NetBIOS, SNMP and SMB all exposed.

Why that order matters: open a null session (net use \\10.20.30.4\\ipc$ with empty credentials), read the SID and note RIDs 500, 501, 512, and 513 (Administrator, Guest, Domain Admins, Domain Users); run enum4linux for users, groups, and shares; walk SNMP with the "public" community for uptime, interfaces, and routes. The output — real account names and share paths — is what the exploitation phase needs next.

How to Study Enumeration for the CEH v13 Exam

To study Module 4:

  1. Memorize the common enumeration ports and their associated protocols (25/SMTP, 137/139/NetBIOS, 161/SNMP, 389/LDAP, 445/SMB)
  2. Understand the SID format and memorize the critical RID values (500, 501, 512, 513, 518-519 for Domain Controllers)
  3. Set up a Windows Server domain controller VM and an attacking Linux VM — practice null session enumeration (enum4linux), SNMP community discovery (snmpwalk), and LDAP queries (ldapsearch)
  4. Review Module 3 (Scanning Networks) for how open ports are found first, and Module 6 (System Hacking) for how enumerated usernames feed brute force attacks

Frequently Asked Questions About Enumeration

What is the difference between enumeration and scanning on the CEH exam?

Scanning (Module 3) identifies open ports and running services — "what is accessible?" Enumeration (Module 4) sends protocol-specific commands to those services to extract actual data — usernames, group memberships, machine names, network shares. Expect scenarios asking which is which, based on the level of detail gathered.

How does SNMP version 3 improve security over v1/v2?

SNMP v1/v2c use plaintext community strings — anyone who knows the string (often "public") can read or modify MIB data. SNMPv3 adds three security models: noAuthNoPriv (no authentication), authNoPriv (authentication, no encryption), and authPriv (authentication with AES/DES encryption), plus per-user credentials instead of shared community strings. Know v3 as the recommended secure implementation and all three levels.

Related CEH v13 Modules

Related Glossary Terms