Cyber Security Basics 📂 Slides · 18 of 18 50 min read

Enumeration & Weaponization: From Open Ports to a Loaded Payload

A visual cyber-security tutorial on two pivotal attack phases. Enumeration turns open ports into real usernames, shares, and services by interrogating talkative protocols — SMB, SNMP, LDAP, DNS, SMTP, NTP. Weaponization welds an exploit to a payload inside a deliverable. Learn the tools, current methods, and the defenses that stop each one.

Enumeration & Weaponization

Two turning points in an attack. Enumeration turns open ports into real names — users, shares, groups, services. Weaponization is the attacker in their workshop, welding an exploit to a payload. Learn both — and how defenders shut each one down.
Users & Shares SNMP · LDAP · SMB Payload Crafting Detection & Defense

Press Next → or use ← → arrow keys

The Big Picture

Where These Two Phases Live

Enumeration is the deep-probe stage after scanning — the attacker is now inside a conversation with your services, pulling out names. Weaponization is the very next kill-chain step after reconnaissance — done quietly on the attacker's own machine.

The Attacker's Path 1 · Reconnaissancegather intel 2 · Weaponizationbuild the weapon 3 · Deliverysend it in → Exploit → Scanningwhat's open? Enumerationwho & what exactly? System Hackingthe foothold
🧭
Two lenses, one attack

The Cyber Kill Chain is the strategic view (Recon → Weaponization → Delivery → …). The CEH hacking phases are the hands-on view (Scanning → Enumeration → System Hacking). This deck covers Enumeration from the hands-on side and Weaponization from the kill-chain side — the two places an attack sharpens into a real threat.

Story

The Locksmith's Notebook

First you read the doors. Then you cut the key.

A locksmith casing a building doesn't stop at "the side door is unlocked." He leans in and reads it — brand of lock, who has keys, the delivery times on the notice board, the cleaner's name on the roster. That is enumeration: not "port 445 is open," but "the server is FILE-SRV01, it shares \\Payroll, and the admin account is jmiller."

Back in his workshop, he files a blank into a working key and tapes it inside a harmless-looking parcel to slip past the front desk. That is weaponization: quiet, offline, invisible to the target — an exploit welded to a payload and wrapped so it looks like an invoice. By the time it arrives, the hard thinking is already done.

⚠️
Why defenders must understand both

Enumeration leaves noise you can catch — floods of SMB/LDAP/SNMP queries. Weaponization leaves almost nothing until it lands. Knowing what the attacker extracts and what they build tells you exactly what to lock down and what to watch for.

Enumeration · Part 1

What Enumeration Really Extracts

Enumeration means opening active connections to a service and querying it directly for information it will happily hand over — often without any credentials at all.

Open Port → Active Query → Real Names Attackerenum4linux query: "list users?" reply: full list ✓ Open ServiceSMB · SNMP · LDAPport 445 / 161 / 389 👤 Usernames & groups 📁 Network shares 🖥️ Machine & domain names ⚙️ Services, versions, policies
💡
The key difference from scanning

Scanning asks "is anyone home?" and gets yes/no. Enumeration walks in and starts a conversation — a full TCP session where the service returns structured data. That data is the raw material for password attacks, privilege escalation, and lateral movement.

Enumeration · Part 1

Scanning vs Enumeration

📡
Scanning — the survey

• Is the host alive?
• Which ports are open?
• Which service & version?
• Often connectionless / half-open
Output: a map of the perimeter

🗝️
Enumeration — the interrogation

• What are the usernames?
• What shares & groups exist?
• What is the domain / OS build?
• Always a full active connection
Output: a target list of real objects

🎯
Why it matters

A username is worth ten open ports. Once an attacker has a valid account name, an open service, and a password policy, they can mount a targeted password-guessing or spraying attack instead of blind noise — and stay under lockout thresholds.

Enumeration · Part 1

The Enumeration Target Map

Each juicy port maps to a protocol that leaks something. This is the attacker's cheat-sheet — and yours.

PortServiceWhat it leaksClassic tool
53DNSZone records, hostnames (via zone transfer)dig / nslookup
25SMTPValid email accounts (VRFY / EXPN / RCPT)telnet / smtp-user-enum
135MSRPCRPC endpoints, interfacesrpcdump / rpcclient
137-139NetBIOSNames, sessions, shares, logged-on usersnbtstat / net view
445SMBShares, users, groups, password policyenum4linux / rpcclient
161/162SNMPInterfaces, routes, ARP, running processessnmpwalk
389/3268LDAPUsers, groups, OUs, whole directory treeldapsearch
123NTPConnected hosts, internal IPs, OS cluesntpdc / ntpq
🚪
Rule of thumb

If a management protocol is reachable from a network it doesn't need to serve, it will be enumerated. SNMP (161) and SMB (445) exposed to the internet are among the most-abused services on earth.

Enumeration · Part 2

NetBIOS & SMB Enumeration

NetBIOS (137-139) and SMB (445) are the classic Windows leak. A null session — connecting with no username and no password — can still return names on older or misconfigured hosts.

Attackernull session connect ""/"" shares + users FILE-SRV01port 445IPC$ open
NetBIOS suffix codes (the <xx> tag)
CodeMeaning
<00>Workstation service
<20>File server (shares present)
<03>Messenger / logged-on user
<1D>Master browser
<1B>Domain master browser (PDC)
🛠️
Commands you'll see

nbtstat -A <ip> · net view \\target · enum4linux -a <ip> · rpcclient -U "" <ip> then enumdomusers. Each one is a full session — noisy, and very catchable in SMB logs.

Enumeration · Part 2

SNMP Enumeration — the Overshare

SNMP was built for network management, so it happily exposes interfaces, routing tables, ARP caches, and running processes — if you know the community string. The catch: defaults are almost universal.

SNMP Managersnmpwalk community: "public" full MIB dump ✓ SNMP Agentrouter / switch / hostport 161 (UDP) 🌐 Interfaces & IPs 🗺️ Routing & ARP tables ⚙️ Running processes
🔑
Default community strings

Read-only: public · Read-write: private. Left unchanged on countless devices. Read-write means an attacker can reconfigure the device, not just read it.

🛡️
Fix

Disable SNMP if unused; move to SNMPv3 (auth + encryption); change community strings; block 161/UDP at the border. snmpwalk -c public -v1 <ip> should return nothing.

Enumeration · Part 2

LDAP Enumeration — Reading the Directory

Active Directory speaks LDAP on 389 (and Global Catalog on 3268). If anonymous or authenticated binds are allowed, the whole organizational tree — users, groups, OUs, even descriptions with passwords in them — can be walked.

ldapsearchbind :389 dc=acme,dc=com ou=Users ou=Groups cn=jmiller (admin) cn=svc_backup cn=Domain Admins
🧰
Modern twist

Tools like BloodHound / SharpHound turn a plain LDAP dump into an attack-path graph: "who can reach Domain Admin, and how." Enumeration output stopped being a list and became a map of privilege.

Enumeration · Part 2

Three More That Talk Too Much

📧
SMTP (25)
User discovery
VRFY bob confirms an account exists; EXPN expands a list; RCPT TO accepts or rejects. Answers reveal valid email addresses for phishing.
🌐
DNS (53)
Zone transfer
A misconfigured server answers AXFR and hands over every record — internal hostnames, mail servers, dev boxes. One request, whole map.
⏰
NTP (123)
Host discovery
ntpdc -c monlist lists recently connected hosts — exposing internal IPs and OS/version clues behind the firewall.
🔎
The pattern is always the same

A protocol built to help — verify a mailbox, sync a clock, replicate a zone — becomes a leak when it answers strangers. Enumeration is simply asking helpful protocols unhelpful questions.

Enumeration · Part 3

The Enumeration Toolkit

🐧
enum4linux-ng
The all-in-one for SMB/NetBIOS — users, shares, groups, password policy, OS in one command.
📶
snmpwalk / onesixtyone
Brute community strings, then walk the full MIB tree of a device.
🌳
ldapsearch / windapsearch
Query and dump Active Directory objects over LDAP.
🔗
rpcclient / nbtstat
Classic Windows RPC and NetBIOS name enumeration.
🗺️
Nmap NSE scripts
smb-enum-*, snmp-*, ldap-*, dns-zone-transfer — enumeration built into the scanner.
🩸
BloodHound / NetExec
Modern AD enumeration at scale — turns dumps into attack-path graphs.
💡
Blue-team move

Run these tools against yourself. If enum4linux -a or an anonymous ldapsearch returns your user list, so will an attacker's — fix it before they find it.

Enumeration · Defense

Shutting Down Enumeration

🛡️ COUNTERMEASURES THAT ACTUALLY MOVE THE NEEDLE
1
Kill null sessions & anonymous binds. Restrict anonymous SMB access; disable anonymous LDAP; enforce SMB signing.
2
Lock down SNMP. Remove it if unused, move to SNMPv3, change default community strings, filter 161/UDP.
3
Restrict DNS zone transfers to authorized secondaries only — never allow AXFR to the world.
4
Disable SMTP VRFY/EXPN and don't leak "user unknown" vs "mailbox full" differences.
5
Segment management protocols. NetBIOS, SMB, SNMP, LDAP should never be reachable from the internet or guest VLANs.
6
Monitor for the noise. Bursts of SMB/LDAP/SNMP queries from one host = someone enumerating. Alert on it.
The Pivot

From Knowing → to Building

Enumeration told the attacker exactly who and what to hit. Now the kill chain rewinds to the step where that knowledge becomes a weapon: Weaponization.

Intelligence in, weapon out.

The attacker now knows the target runs an unpatched PDF reader, that jmiller handles invoices, and that macros aren't blocked on the finance team's laptops. Reconnaissance and enumeration handed over a shopping list. In the workshop, that list gets turned into a single, tailored, deliverable weapon — long before anything is ever sent.

🕳️
The blind spot

Weaponization happens entirely on the attacker's own infrastructure. There is no packet to catch, no log on your side. This is the one kill-chain phase you generally cannot observe — which is exactly why understanding it matters.

Weaponization · Part 1

What Is Weaponization?

Weaponization is Phase 2 of the Cyber Kill Chain: coupling an exploit (the thing that breaks in) with a payload / backdoor (the thing that stays), then wrapping both in a deliverable the target will open.

ExploitCVE / macro / vuln + Backdoorbeacon / RAT / shell WeaponizedDeliverableinvoice.docm ready todeliver →
🧩
Three ingredients

Exploit = the crack (an unpatched CVE, a macro, a logic flaw). Payload = what runs after (a reverse shell, a Cobalt Strike beacon, ransomware). Wrapper = the disguise (a document, an installer, an ISO) that gets it past a human and a mail filter.

Story

The Loaded Invoice

It looks like a bill. It's a doorway.

The attacker opens a document that looks exactly like a supplier invoice — logo, line items, a plausible total. Hidden inside is a small macro. When jmiller clicks "Enable Content," the macro quietly reaches out to a server the attacker controls and pulls down the real payload. No exploit code even ships in the file — just a lure and a launcher.

Every choice was made because of enumeration: a Word document because macros work on that team, an invoice because jmiller processes them daily, a filename that matches a real vendor found during recon. The weapon is tailored, tested against antivirus offline, and only then sent.

✅
Where defenders win

You can't see the file being built — but you can block macros from the internet by default, strip active content at the mail gateway, and detonate attachments in a sandbox before they reach the inbox. The weapon fails at the door.

Weaponization · Part 2

Inside the Weaponization Workshop

The attacker's build pipeline is a repeatable assembly line — each step chosen from the intel gathered earlier.

1 · Pick exploitmatch to enum data 2 · Generate payloadmsfvenom / C2 beacon 3 · Bind to luredoc / PDF / installer 4 · Obfuscatepack / crypt / encode 5 · Test vs AVtweak until clean ✔ Weapon readyhand off to delivery
🔁
The loop that beats antivirus

Steps 4-5 repeat: obfuscate, scan against a private AV bank, tweak, repeat — until the sample is fully undetectable (FUD). Because this happens offline on the attacker's machine, signature-only defenses are testing against a weapon they've never seen.

Weaponization · Part 2

The Deliverables Attackers Build

📄
Macro documents
.docm / .xlsm
VBA macros that download a payload. The classic — now dented by Microsoft blocking macros from the internet by default.
🗜️
Container files
.iso / .img / .zip
Wrap the payload in a mounted image to bypass the "Mark of the Web" that would otherwise warn the user.
🔗
Shortcut & script files
.lnk / .js / .hta
A shortcut that quietly runs PowerShell; a script host file that never looks like an executable.
📑
Malicious PDFs
reader exploits
Exploit an unpatched PDF reader, or embed a link/launch action to fetch the next stage.
📦
Trojanized installers
fake "setup.exe"
A real, working app bundled with a hidden payload — often pushed via SEO'd fake download sites.
🧰
Exploit kits
drive-by
Server-side toolkits that fingerprint a browser and auto-serve the matching exploit on visit.
Weaponization · Part 2

Build-Time Evasion

Half the workshop is spent not building the weapon but hiding it — defeating the scanner before the file is ever sent.

TechniqueWhat it doesDefeats
PackingCompresses/wraps the binary so its code isn't visible on diskStatic signatures
CryptingEncrypts the payload; a small stub decrypts it in memory at runtimeOn-disk AV scans
EncodingRe-encodes shellcode (e.g. msfvenom encoders) to change its bytesByte-pattern rules
ObfuscationRenames/mangles macro & script code so it reads as gibberishKeyword detection
Signing abuseSigns the file with a stolen or bought code-signing certificateTrust checks
Sandbox checksPayload sleeps or checks for VM/analysis before runningAutomated sandboxes
🧠
Why behavior beats signatures here

Every technique above changes how the file looks, not what it does. That's why modern defense leans on behavioral / EDR detection — a document spawning PowerShell that calls out to the internet is suspicious no matter how it's packed.

Weaponization · Current

What Attackers Weaponize Now

As old tricks get blocked, the workshop adapts. The 2024-2025 shift, in short: away from macros, toward containers and scripts.

📉
Fading

• Office macros from the internet — blocked by default since 2022
• Naked .exe attachments — filtered everywhere
• Reused, known-signature payloads

📈
Rising

• HTML smuggling — the payload is assembled in the browser
• ISO / IMG / OneNote containers that dodge Mark-of-the-Web
• LNK + LOLBins — living off the land (mshta, rundll32)
• AI-assisted lure and obfuscation generation

💡
The through-line

Attackers move to whatever format users still open and filters still trust. Defense follows the same logic in reverse: block the risky container, strip active content, and watch what the file does after it opens.

Weaponization · Defense

Defending an Invisible Phase

🕶️
You can't watch the build — so watch the edges

Weaponization itself is offline and unobservable. Defense targets the moments around it: the indicators the finished weapon carries, and the behavior it shows the instant it's delivered.

🛡️ WHAT ACTUALLY WORKS
1
Block risky deliverables at the gateway — macros from the internet, ISO/IMG, HTA, LNK. Strip active content.
2
Detonate in a sandbox before delivery; use content disarm & reconstruction (CDR) to rebuild files clean.
3
Deploy EDR / behavioral detection — catch document-spawns-PowerShell-calls-internet regardless of packing.
4
Patch relentlessly. A weapon built around an unpatched CVE is a dud on a patched host.
5
Hunt shared indicators — YARA rules, C2 domains, payload hashes from threat intel feeds.
Recap

Golden Rules — Both Phases

🏆 CARRY THESE OUT OF THE ROOM
1
Enumeration = active conversation. Scanning finds doors; enumeration reads what's written on them.
2
Helpful protocols leak. SMB, SNMP, LDAP, DNS, SMTP, NTP all overshare when they answer strangers.
3
A valid username beats ten open ports. Names turn blind noise into targeted attacks.
4
Weaponization = exploit + payload + wrapper, built offline and tested against AV until clean.
5
You can't see the workshop. Defend the deliverable and the behavior, not the build.
6
Enumerate yourself first. Everything an attacker learns, you can learn earlier — and fix.
FINAL

From Recon Noise to a Loaded Weapon

445 · 161 · 389Most-abused enum ports
null sessionThe oldest leak
exploit + payload= weapon
FUDThe attacker's goal
🎯
The whole idea

Enumeration is the attacker turning open ports into a precise target list — real users, shares, and services pulled straight from talkative protocols. Weaponization is that list becoming a tailored, tested weapon in a workshop you can't see. Defenders win by silencing the oversharing services and blocking & detonating the deliverables — starving both phases of what they need.

🧠
One sentence to remember

Enumeration asks helpful protocols unhelpful questions; weaponization welds an exploit to a payload behind closed doors. Next in the kill chain: Delivery & Exploitation — where the weapon finally leaves the workshop.

🗝️ End of tutorial · Press ← to review, or click Restart

You have completed Slides. View all sections →