The RID_ENUM utility (or Rid Enum) performs a cycling attack to attempt retrieving all users from a Windows domain controller. It focuses on retrieving identities from the domain admins group. The attack will work to versions, with Windows 2003 being the latest. This was to ensure compatibility with previous versions of Windows. Windows 2008 and later will not allow this type of enumeration to happen.

  • + The source code of this software is available

RID_ENUM is under development by David Kennedy.



  • pexpect

Similar tools to RID_ENUM:



LinEnum can be used during penetration tests to perform scripted local Linux enumeration and check for privilege escalations.



Massh-enum is a user enumeration tool for OpenSSH with the goal to find valid usernames. Read how it works in this review.

