Enumeration & Weaponization
Press Next → or use ← → arrow keys
Where These Two Phases Live
Enumeration is the deep-probe stage after scanning — the attacker is now inside a conversation with your services, pulling out names. Weaponization is the very next kill-chain step after reconnaissance — done quietly on the attacker's own machine.
The Cyber Kill Chain is the strategic view (Recon → Weaponization → Delivery → …). The CEH hacking phases are the hands-on view (Scanning → Enumeration → System Hacking). This deck covers Enumeration from the hands-on side and Weaponization from the kill-chain side — the two places an attack sharpens into a real threat.
The Locksmith's Notebook
A locksmith casing a building doesn't stop at "the side door is unlocked." He leans in and reads it — brand of lock, who has keys, the delivery times on the notice board, the cleaner's name on the roster. That is enumeration: not "port 445 is open," but "the server is FILE-SRV01, it shares \\Payroll, and the admin account is jmiller."
Back in his workshop, he files a blank into a working key and tapes it inside a harmless-looking parcel to slip past the front desk. That is weaponization: quiet, offline, invisible to the target — an exploit welded to a payload and wrapped so it looks like an invoice. By the time it arrives, the hard thinking is already done.
Enumeration leaves noise you can catch — floods of SMB/LDAP/SNMP queries. Weaponization leaves almost nothing until it lands. Knowing what the attacker extracts and what they build tells you exactly what to lock down and what to watch for.
What Enumeration Really Extracts
Enumeration means opening active connections to a service and querying it directly for information it will happily hand over — often without any credentials at all.
Scanning asks "is anyone home?" and gets yes/no. Enumeration walks in and starts a conversation — a full TCP session where the service returns structured data. That data is the raw material for password attacks, privilege escalation, and lateral movement.
Scanning vs Enumeration
• Is the host alive?
• Which ports are open?
• Which service & version?
• Often connectionless / half-open
Output: a map of the perimeter
• What are the usernames?
• What shares & groups exist?
• What is the domain / OS build?
• Always a full active connection
Output: a target list of real objects
A username is worth ten open ports. Once an attacker has a valid account name, an open service, and a password policy, they can mount a targeted password-guessing or spraying attack instead of blind noise — and stay under lockout thresholds.
The Enumeration Target Map
Each juicy port maps to a protocol that leaks something. This is the attacker's cheat-sheet — and yours.
| Port | Service | What it leaks | Classic tool |
|---|---|---|---|
| 53 | DNS | Zone records, hostnames (via zone transfer) | dig / nslookup |
| 25 | SMTP | Valid email accounts (VRFY / EXPN / RCPT) | telnet / smtp-user-enum |
| 135 | MSRPC | RPC endpoints, interfaces | rpcdump / rpcclient |
| 137-139 | NetBIOS | Names, sessions, shares, logged-on users | nbtstat / net view |
| 445 | SMB | Shares, users, groups, password policy | enum4linux / rpcclient |
| 161/162 | SNMP | Interfaces, routes, ARP, running processes | snmpwalk |
| 389/3268 | LDAP | Users, groups, OUs, whole directory tree | ldapsearch |
| 123 | NTP | Connected hosts, internal IPs, OS clues | ntpdc / ntpq |
If a management protocol is reachable from a network it doesn't need to serve, it will be enumerated. SNMP (161) and SMB (445) exposed to the internet are among the most-abused services on earth.
NetBIOS & SMB Enumeration
NetBIOS (137-139) and SMB (445) are the classic Windows leak. A null session — connecting with no username and no password — can still return names on older or misconfigured hosts.
| Code | Meaning |
|---|---|
| <00> | Workstation service |
| <20> | File server (shares present) |
| <03> | Messenger / logged-on user |
| <1D> | Master browser |
| <1B> | Domain master browser (PDC) |
nbtstat -A <ip> · net view \\target · enum4linux -a <ip> · rpcclient -U "" <ip> then enumdomusers. Each one is a full session — noisy, and very catchable in SMB logs.
SNMP Enumeration — the Overshare
SNMP was built for network management, so it happily exposes interfaces, routing tables, ARP caches, and running processes — if you know the community string. The catch: defaults are almost universal.
Read-only: public · Read-write: private. Left unchanged on countless devices. Read-write means an attacker can reconfigure the device, not just read it.
Disable SNMP if unused; move to SNMPv3 (auth + encryption); change community strings; block 161/UDP at the border. snmpwalk -c public -v1 <ip> should return nothing.
LDAP Enumeration — Reading the Directory
Active Directory speaks LDAP on 389 (and Global Catalog on 3268). If anonymous or authenticated binds are allowed, the whole organizational tree — users, groups, OUs, even descriptions with passwords in them — can be walked.
Tools like BloodHound / SharpHound turn a plain LDAP dump into an attack-path graph: "who can reach Domain Admin, and how." Enumeration output stopped being a list and became a map of privilege.
Three More That Talk Too Much
VRFY bob confirms an account exists; EXPN expands a list; RCPT TO accepts or rejects. Answers reveal valid email addresses for phishing.AXFR and hands over every record — internal hostnames, mail servers, dev boxes. One request, whole map.ntpdc -c monlist lists recently connected hosts — exposing internal IPs and OS/version clues behind the firewall.A protocol built to help — verify a mailbox, sync a clock, replicate a zone — becomes a leak when it answers strangers. Enumeration is simply asking helpful protocols unhelpful questions.
The Enumeration Toolkit
smb-enum-*, snmp-*, ldap-*, dns-zone-transfer — enumeration built into the scanner.Run these tools against yourself. If enum4linux -a or an anonymous ldapsearch returns your user list, so will an attacker's — fix it before they find it.
Shutting Down Enumeration
AXFR to the world.From Knowing → to Building
Enumeration told the attacker exactly who and what to hit. Now the kill chain rewinds to the step where that knowledge becomes a weapon: Weaponization.
The attacker now knows the target runs an unpatched PDF reader, that jmiller handles invoices, and that macros aren't blocked on the finance team's laptops. Reconnaissance and enumeration handed over a shopping list. In the workshop, that list gets turned into a single, tailored, deliverable weapon — long before anything is ever sent.
Weaponization happens entirely on the attacker's own infrastructure. There is no packet to catch, no log on your side. This is the one kill-chain phase you generally cannot observe — which is exactly why understanding it matters.
What Is Weaponization?
Weaponization is Phase 2 of the Cyber Kill Chain: coupling an exploit (the thing that breaks in) with a payload / backdoor (the thing that stays), then wrapping both in a deliverable the target will open.
Exploit = the crack (an unpatched CVE, a macro, a logic flaw). Payload = what runs after (a reverse shell, a Cobalt Strike beacon, ransomware). Wrapper = the disguise (a document, an installer, an ISO) that gets it past a human and a mail filter.
The Loaded Invoice
The attacker opens a document that looks exactly like a supplier invoice — logo, line items, a plausible total. Hidden inside is a small macro. When jmiller clicks "Enable Content," the macro quietly reaches out to a server the attacker controls and pulls down the real payload. No exploit code even ships in the file — just a lure and a launcher.
Every choice was made because of enumeration: a Word document because macros work on that team, an invoice because jmiller processes them daily, a filename that matches a real vendor found during recon. The weapon is tailored, tested against antivirus offline, and only then sent.
You can't see the file being built — but you can block macros from the internet by default, strip active content at the mail gateway, and detonate attachments in a sandbox before they reach the inbox. The weapon fails at the door.
Inside the Weaponization Workshop
The attacker's build pipeline is a repeatable assembly line — each step chosen from the intel gathered earlier.
Steps 4-5 repeat: obfuscate, scan against a private AV bank, tweak, repeat — until the sample is fully undetectable (FUD). Because this happens offline on the attacker's machine, signature-only defenses are testing against a weapon they've never seen.
The Deliverables Attackers Build
Build-Time Evasion
Half the workshop is spent not building the weapon but hiding it — defeating the scanner before the file is ever sent.
| Technique | What it does | Defeats |
|---|---|---|
| Packing | Compresses/wraps the binary so its code isn't visible on disk | Static signatures |
| Crypting | Encrypts the payload; a small stub decrypts it in memory at runtime | On-disk AV scans |
| Encoding | Re-encodes shellcode (e.g. msfvenom encoders) to change its bytes | Byte-pattern rules |
| Obfuscation | Renames/mangles macro & script code so it reads as gibberish | Keyword detection |
| Signing abuse | Signs the file with a stolen or bought code-signing certificate | Trust checks |
| Sandbox checks | Payload sleeps or checks for VM/analysis before running | Automated sandboxes |
Every technique above changes how the file looks, not what it does. That's why modern defense leans on behavioral / EDR detection — a document spawning PowerShell that calls out to the internet is suspicious no matter how it's packed.
What Attackers Weaponize Now
As old tricks get blocked, the workshop adapts. The 2024-2025 shift, in short: away from macros, toward containers and scripts.
• Office macros from the internet — blocked by default since 2022
• Naked .exe attachments — filtered everywhere
• Reused, known-signature payloads
• HTML smuggling — the payload is assembled in the browser
• ISO / IMG / OneNote containers that dodge Mark-of-the-Web
• LNK + LOLBins — living off the land (mshta, rundll32)
• AI-assisted lure and obfuscation generation
Attackers move to whatever format users still open and filters still trust. Defense follows the same logic in reverse: block the risky container, strip active content, and watch what the file does after it opens.
Defending an Invisible Phase
Weaponization itself is offline and unobservable. Defense targets the moments around it: the indicators the finished weapon carries, and the behavior it shows the instant it's delivered.
Golden Rules — Both Phases
From Recon Noise to a Loaded Weapon
Enumeration is the attacker turning open ports into a precise target list — real users, shares, and services pulled straight from talkative protocols. Weaponization is that list becoming a tailored, tested weapon in a workshop you can't see. Defenders win by silencing the oversharing services and blocking & detonating the deliverables — starving both phases of what they need.
Enumeration asks helpful protocols unhelpful questions; weaponization welds an exploit to a payload behind closed doors. Next in the kill chain: Delivery & Exploitation — where the weapon finally leaves the workshop.
🗝️ End of tutorial · Press ← to review, or click Restart