Agent skill

Smb Enumeration

by blacklanternsecurity in blacklanternsecurity/red-run

SMB share enumeration, access testing, password policy extraction, and content searching.

GPL-3.0Auto-check passedSecurity

Install Smb Enumeration

skills CLI
$ npx skills add blacklanternsecurity/red-run --skill smb-enumeration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install blacklanternsecurity/red-run smb-enumeration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/blacklanternsecurity/red-run.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/network/smb-enumeration .claude/skills/smb-enumeration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
smb-enumeration
GitHub stars
287
Token cost
~3k tokens
SKILL.md length
1,089 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
GPL-3.0

At a glance

SMB share enumeration, access testing, password policy extraction, and content searching.

  • Works in 8 steps: Share Listing → Password/Lockout Policy → User and Vulnerability Enumeration via NSE → …
  • Security work in your project
  • SKILL.md covers Engagement Logging, Scope Boundary, What This Skill Does NOT Do and State Management, plus 10 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Smb Enumeration is an agent skill from blacklanternsecurity/red-run. SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon identifies SMB ports (139/445).

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: Offensive security toolkit for Claude Code. The licence is GPL-3.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/smb-enumeration”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Share Listing
  2. Password/Lockout Policy
  3. User and Vulnerability Enumeration via NSE
  4. Per-Share Access Testing (MANDATORY)
  5. Fallback Share Probing
  6. Content Search with MANSPIDER
  7. Authenticated Re-enumeration
  8. Escalate or Pivot

What it can do on your machine

Read from SKILL.md and the folder at commit 050ac1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Smb Enumeration loads about 3k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,089 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from blacklanternsecurity/red-run at commit 050ac1f, republished under its GPL-3.0 licence (© blacklanternsecurity). 1,089 words, ~3,017 tokens.

Download SKILL.mdSave it as .claude/skills/smb-enumeration/SKILL.md (or your agent's skills folder).
name
smb-enumeration
description
SMB share enumeration, access testing, password policy extraction, and content searching. Enumerates shares via null session, guest, and authenticated access. Covers share listing, per-share access testing, MANSPIDER content search, and SMB vulnerability detection (signing, EternalBlue). Use after network-recon identifies SMB ports (139/445).
keywords
SMB shares, null session, guest access, smbclient, enum4linux, MANSPIDER, SMB signing, share enumeration, password policy, NetExec smb
tools
smbclient, NetExec, enum4linux-ng, MANSPIDER, nmap
opsec
medium

SMB Enumeration

You are helping a penetration tester enumerate SMB services on a target host. All testing is under explicit written authorization.

Engagement Logging

Check for ./engagement/ directory. If absent, proceed without logging.

When an engagement directory exists:

  • Print [smb-enumeration] Activated → <target> to the screen on activation.
  • Evidence → save significant output to engagement/evidence/ with descriptive filenames (e.g., smb-shares-10.10.10.5.txt, smb-manspider-results.txt).

Scope Boundary

This skill covers SMB enumeration only — share listing, access testing, content searching, and vulnerability detection. When you reach the boundary of this scope, STOP.

Do not load or execute another skill. Return to the orchestrator with:

  • What was found (shares, credentials, vulnerabilities)
  • Recommended next skill
  • Context to pass (DC IP, domain name, credentials, share paths)

Routing boundaries:

  • RCE exploitation (EternalBlue, SMBGhost, PrintNightmare)
  • Domain enumeration (LDAP, BloodHound, GPP)
  • Password brute forcing or spraying
  • Writable share abuse (web shells, DLL hijack)

Stay in methodology. Only use techniques documented in this skill.

What This Skill Does NOT Do

  • Exploit SMB vulnerabilities (EternalBlue, SMBGhost, PrintNightmare)
  • Perform password spraying or brute force attacks
  • Run Active Directory enumeration (LDAP queries, BloodHound)
  • Abuse writable shares for code execution or relay NTLM authentication

These are handled by dedicated skills. This skill discovers and reports.

State Management

Call get_state_summary() to read current engagement state. Use it to:

  • Skip re-testing targets already enumerated for SMB
  • Leverage existing credentials for authenticated enumeration (Step 7)
  • Check what's been tried and failed (Blocked section)

State writes — write critical discoveries immediately:

  • SMB signing disabled → add_vuln(title="SMB signing disabled on <host>", host="<host>", vuln_type="smb-signing", severity="medium")
  • Null session or guest access → add_vuln(title="SMB null/guest access on <host>", host="<host>", vuln_type="null-session", severity="medium")
  • EternalBlue confirmed → add_vuln(title="MS17-010 EternalBlue on <host>", host="<host>", vuln_type="rce", severity="critical")
  • Domain name/hostnames from SMB → add_pivot(source="SMB on <host>", destination="<domain>/<hostname>", method="SMB OS discovery")
  • Credentials found in share files → add_credential(username="<user>", secret="<password>", secret_type="password", source="SMB share file <path>")

Return summary must include:

  • Per-share access table (mandatory — every share gets a row)
  • Account lockout policy (if enumerable)
  • Domain/hostname info discovered
  • Credentials found
  • Vulnerabilities confirmed (signing, null session, EternalBlue)

Prerequisites

  • Network access to SMB ports (139/445) on target
  • Target IP address (provided by orchestrator or operator)
  • Optional: credentials for authenticated enumeration (passed by orchestrator)

Step 1: Share Listing

Run ALL of the following tools in sequence — not just one. SMB tools use different RPC calls and authentication methods under the hood. A failure or partial result from one tool does NOT mean the others will also fail. NetExec might return STATUS_USER_SESSION_DELETED while smbclient -L succeeds, or vice versa. You must try every tool before concluding that SMB enumeration has failed.

bash
# Tool 1: smbclient null session share listing
smbclient -N -L //TARGET_IP/

# Tool 2: NetExec null session + guest
netexec smb TARGET_IP -u '' -p '' --shares
netexec smb TARGET_IP -u 'guest' -p '' --shares

# Tool 3: enum4linux-ng comprehensive enumeration
enum4linux-ng -A TARGET_IP

Collect all unique share names from ALL tools. A share discovered by any tool counts — even if other tools failed to list it.

Step 2: Password/Lockout Policy

bash
netexec smb TARGET_IP -u '' -p '' --pass-pol
netexec smb TARGET_IP -u 'guest' -p '' --pass-pol

If either succeeds, record the full policy. The orchestrator needs this before routing to password-spraying. Key values: lockout threshold (0 = no lockout — critical for spray decisions), observation window, lockout duration, min password length, complexity requirements.

Step 3: User and Vulnerability Enumeration via NSE

bash
nmap -sV -p445 --script smb-enum-shares,smb-enum-users,smb-os-discovery,smb-vuln* TARGET_IP

Check results for: SMB signing status, OS version, EternalBlue (ms17-010), SMBGhost (CVE-2020-0796), user accounts enumerated.

Step 4: Per-Share Access Testing (MANDATORY)

This step is NOT optional. Test every share individually with smbclient. Access denied on one share tells you NOTHING about other shares — Windows ACLs are per-share. Skipping a share is a methodology failure.

For EVERY share discovered in Steps 1 and 3 (from ANY tool), run:

bash
smbclient //TARGET_IP/SHARENAME -N -c 'ls' 2>&1

If ls succeeds (shows files/directories), the share is readable. Follow up:

bash
# Recursive listing of accessible share
smbclient //TARGET_IP/SHARENAME -N -c 'recurse ON; prompt OFF; ls'

# Download interesting files (configs, scripts, credentials, backups)
smbclient //TARGET_IP/SHARENAME -N -c 'recurse ON; prompt OFF; mget *'
Show full SKILL.md (527 more words)Show less
Write Access Verification

For every readable share, test write access with an actual file upload. Share-level ACLs (what nxc --shares reports) can differ from NTFS filesystem ACLs. The only reliable way to determine write access is to attempt a write.

bash
# Test write — lcd avoids smbclient path resolution issues
smbclient //TARGET_IP/SHARENAME -N -c 'lcd /tmp; put /etc/hostname .write-test'
# Clean up on success
smbclient //TARGET_IP/SHARENAME -N -c 'del .write-test'

If the smbclient write fails but nxc --shares reported WRITE for this share, retry with a second tool before concluding read-only. Different SMB clients use different dialect negotiation and session handling — one tool failing does not mean writes are blocked:

bash
# Fallback write test with impacket
impacket-smbclient -no-pass TARGET_IP
# At prompt: use SHARENAME, then: put /etc/hostname .write-test
# Clean up: del .write-test

Mark the share as WRITE only after a successful file upload. Mark as READ only after two tools fail to write.

Per-share results table (mandatory in return summary). Every share must have a row. No share may be listed as "not tested".

| Share | Access | Method | Contents/Notes |
|-------|--------|--------|----------------|
| ADMIN$ | DENIED | smbclient -N | NT_STATUS_ACCESS_DENIED |
| C$ | DENIED | smbclient -N | NT_STATUS_ACCESS_DENIED |
| Development | READ | smbclient -N, write failed (2 tools) | Automation/ directory found |
| Shared | WRITE | smbclient -N | Empty, write confirmed via put |
| IPC$ | LIMITED | smbclient -N | IPC only, no file listing |
| NETLOGON | READ | smbclient -N, write failed (2 tools) | Empty or standard scripts |
| SYSVOL | READ | smbclient -N, write failed (2 tools) | Policies, scripts |

Rules:

  • "Access" must be one of: READ, WRITE, DENIED, LIMITED, ERROR
  • WRITE requires a successful file upload — never infer from share ACL metadata alone
  • READ requires write failure from at least two tools (smbclient + one fallback)
  • "Method" must show the actual command used
  • Never report a share as DENIED unless you received NT_STATUS_ACCESS_DENIED (or similar error) from testing THAT SPECIFIC share
  • Never infer access status from other shares — test each one individually
  • If smbclient hangs or times out on a share, report as ERROR with details

Step 5: Fallback Share Probing

Only if ALL listing tools in Step 1 failed. Some Windows configurations block null-session share listing but allow null-session access to individual shares:

bash
for share in ADMIN$ C$ IPC$ SYSVOL NETLOGON Development Users Backups Public Data IT HR Finance Software Shared Docs; do
    echo "--- $share ---"
    smbclient //TARGET_IP/"$share" -N -c 'ls' 2>&1 | head -20
done

Step 6: Content Search with MANSPIDER

After identifying accessible shares, search file contents for credentials and sensitive data. MANSPIDER crawls SMB shares and greps file contents (including Office docs, PDFs, and archives) without downloading everything.

Only run after the share access table is complete — needs at least one readable share. If all shares returned DENIED, skip this step.

bash
# Keyword search for passwords and credentials
manspider TARGET_IP -c password passwd cred secret
manspider TARGET_IP -c connectionstring server= uid= pwd=

# Regex search for credential patterns
manspider TARGET_IP -e '(password|passwd|pwd)\s*[=:]\s*\S+'

# Limit to specific file types
manspider TARGET_IP -e 'password' -f xml conf config ini txt ps1 bat vbs

Step 7: Authenticated Re-enumeration

If the orchestrator passes credentials, repeat Steps 1, 4 (including write verification), and 6 with creds.

Shell-special characters in passwords (!, @, $, *, backticks): store the password in a file and reference it to avoid shell expansion issues.

bash
# Store password safely (do this first if password contains special chars)
echo -n 'PASSWORD' > /tmp/claude-1000/pass.txt

# Share listing
netexec smb TARGET_IP -u 'USERNAME' -p "$(cat /tmp/claude-1000/pass.txt)" -d DOMAIN --shares

# Per-share read + write testing (lcd before put — see Step 4)
smbclient //TARGET_IP/SHARENAME -U 'DOMAIN/USERNAME%PASSWORD' -c 'ls' 2>&1
smbclient //TARGET_IP/SHARENAME -U 'DOMAIN/USERNAME%PASSWORD' -c 'lcd /tmp; put /etc/hostname .write-test; del .write-test'

# Content search
manspider TARGET_IP -u 'USERNAME' -p 'PASSWORD' -d DOMAIN -c password secret

Update the per-share access table with authenticated results. Follow the same write verification rules as Step 4 — test every readable share for write access, retry with a second tool on discrepancies.

Step 8: Escalate or Pivot

After completing enumeration:

  • EternalBlue/SMBGhost confirmed → STOP. Recommend smb-exploitation. Pass: host, vuln type, OS version.
  • Domain info discovered → STOP. Recommend ad-discovery. Pass: DC IP, domain name, creds/null session.
  • Password policy extracted (lockout=0) → STOP. Recommend password-spraying. Pass: policy, usernames.
  • Credentials found in shares → STOP. Recommend ad-discovery or authenticated re-enumeration.
  • Writable shares found → STOP. Recommend smb-exploitation. Pass: share name, write method.
  • All shares denied, no vulns → Report complete. No further SMB enumeration without creds.

Troubleshooting

smbclient hangs or times out

Add -t 10 for a 10-second timeout. Verify port 445 is open with nmap.

NT_STATUS_CONNECTION_DISCONNECTED

Target rejecting null sessions. Try guest: -U 'guest%'. If guest also fails, enumeration requires credentials.

enum4linux-ng not found

Fall back to enum4linux (Perl version) or rely on smbclient + NetExec. Do not install — report missing.

NetExec STATUS_USER_SESSION_DELETED

Common and does NOT mean SMB is inaccessible. Continue with smbclient and enum4linux-ng.

MANSPIDER permission errors

Permission errors on ADMIN$/C$ are expected. Verify it crawled readable shares from Step 4.

© blacklanternsecurity, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/network/smb-enumeration of blacklanternsecurity/red-run.

Open the folder on GitHubat commit 050ac1f

Compare with similar skills

Smb Enumeration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Smb Enumeration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Smb Enumeration this skillblacklanternsecurity/red-run287—~3kAutomated safety check: PassGPL-3.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from blacklanternsecurity/red-run

  • Source Code Review

    blacklanternsecurity/red-run

    Security-focused source code review. An agent skill from blacklanternsecurity/red-run.

    287 GitHub stars~1.8k tokensUpdated 9 days ago
    Auto-check: notes
  • Infrastructure Enumeration

    blacklanternsecurity/red-run

    Enumeration of infrastructure services: DNS, SMTP, SNMP, IPMI, NFS, TFTP, RPC/MSRPC, and HTTP/HTTPS surface detection.

    287 GitHub stars~2.4k tokensUpdated 9 days ago
    Auto-check: notes
  • Kerberos Roasting

    blacklanternsecurity/red-run

    Extracts and cracks Kerberos service tickets (Kerberoasting) and AS-REP hashes (AS-REP Roasting) for offline password recovery.

    287 GitHub stars~3.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Trust Attacks

    blacklanternsecurity/red-run

    Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

    287 GitHub stars~4.5k tokensUpdated 9 days ago
    Auto-check: notes
  • Av Edr Evasion

    blacklanternsecurity/red-run

    Bypass antivirus and EDR detection for payload delivery during exploitation.

    287 GitHub stars~5.4k tokensUpdated 9 days ago
    Auto-check: notes

Categories

Questions about Smb Enumeration

What does Smb Enumeration do?

SMB share enumeration, access testing, password policy extraction, and content searching. Smb Enumeration is an agent skill from blacklanternsecurity/red-run. SMB share enumeration, access testing, password policy extraction, and content searching.

When should I use Smb Enumeration?

Smb Enumeration fits situations like: security work in your project.

How do I install Smb Enumeration in Claude Code?

Run `npx skills add blacklanternsecurity/red-run --skill smb-enumeration -a claude-code`. Or copy the skill folder (skills/network/smb-enumeration in blacklanternsecurity/red-run) into .claude/skills/smb-enumeration in your project. Claude Code loads it when a task matches its description.

How do I install Smb Enumeration in Codex?

Run `npx skills add blacklanternsecurity/red-run --skill smb-enumeration -a codex`. Or copy the skill folder (skills/network/smb-enumeration in blacklanternsecurity/red-run) into .agents/skills/smb-enumeration in your project. Codex loads it when a task matches its description.

Can I use Smb Enumeration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add blacklanternsecurity/red-run --skill smb-enumeration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/smb-enumeration, .gemini/skills/smb-enumeration, .github/skills/smb-enumeration and .opencode/skills/smb-enumeration in your project.

What does Smb Enumeration need to run?

SKILL.md names no scripts, command-line tools or credentials: Smb Enumeration is instructions for the agent only.

Does Smb Enumeration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Smb Enumeration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Smb Enumeration use?

Smb Enumeration is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Smb Enumeration use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Smb Enumeration?

Skills that share tags, products or a category with Smb Enumeration: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Smb Enumeration?

blacklanternsecurity (a GitHub organization) maintains it in blacklanternsecurity/red-run, which has 287 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 28, 2026.

Source: blacklanternsecurity/red-run on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.