Sam
Commands for interacting with a remote Security Accounts Manager
Synopsis
Sam <subcommand>
Subcommands
| Command | Description |
|---|---|
| aliasmembers | Gets the members of an alias |
| enumaliases | Enumerates aliases |
| enumgroups | Enumerates groups |
| enumusers | Enumerates user accounts |
For help on a subcommand, use Sam <subcommand> -h
Sam aliasmembers
Gets the members of an alias
Synopsis
Sam aliasmembers [options] <ServerName> [ <AliasRidOrName> ]
Parameters
| Name | Aliases | Value | Description |
|---|---|---|---|
| <ServerName> | <String> | RPC server to interact with | |
| -AliasRidOrName | <String[]> | Name or RID of alias |
Options
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AliasRidOrName | <String[]> | Name or RID of alias | |
| -AuthEpm | <SwitchParam> | Authenticates EP mapper requests | |
| -AuthProxy | <EndPoint> | Endpoint of auth proxy | |
| -ConsoleOutputStyle | -OutputStyle | <OutputStyle> | Determines the output style |
| Possible values: | |||
| Freeform | |||
| Raw | |||
| Table | |||
| List | |||
| Csv | |||
| Tsv | |||
| Json | |||
| TreeTable | |||
| -ContinueOnError | <SwitchParam> | Continue even if errors occur | |
| Default: True | |||
| -Delegate | <SwitchParam> | Requests delegation (sends TGT and key for Kerberos) | |
| -EncryptEpm | <SwitchParam> | Encrypts EP mappend requests | |
| -EncryptRpc | <SwitchParam> | Encrypts RPC messages | |
| -OutputFields | <String[]> | Fields to display in output | |
| Possible values: | |||
| DomainName | |||
| DomainSid | |||
| GroupName | |||
| GroupRid | |||
| MemberSid | |||
| MemberName | |||
| -OutputHeaders | <SwitchParam> | Print headers for table/list/CSV/TSV styles | |
| Default: True | |||
| -PreferSmb | <SwitchParam> | If the interface supports named pipes, attempt to connect over the named pipe instead of TCP | |
| -RpcCallTimeout | <Duration> | Time to wait for RPC calls | |
| -RpcConnectTimeout | <Duration> | Time to wait for RPC connections | |
| -Socks5 | <host-or-ip:port> | End point of SOCKS 5 server to use | |
| -Spnego | <SwitchParam> | Uses SP-NEGO for authentication | |
| -SpnOverride | <SpnMapping[]> | Specifies an SPN override |
Authentication
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Anonymous | <SwitchParam> | Uses anonymous login | |
| -NtlmHash | <hexadecimal hash> | NTLM hash for NTLM authentication | |
| -Password | -p | <String> | Password to authenticate with |
| -UserDomain | -ud | <String> | Domain of user to authenticate with |
| -UserName | -u | <UserPrincipalName> | User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AesKey | <HexString> | AES key (128 or 256) | |
| -DelegateTicket | <String[]> | Sends the tickets (and keys) to the target for delegation | |
| -DesKey | <HexString> | DES key | |
| -Kdc | <host-or-ip:port> | KDC endpoint | |
| -Keytab | <String> | Name of keytab file | |
| -S4ProxyService | <SecurityPrincipalName> | Name of service to proxy through | |
| -S4UserCert | <String> | Name of file containing a certificate of a user to impersonate with S4U | |
| -S4UserName | <UserPrincipalName> | Name of user to impersonate with S4U | |
| -Tgt | <String> | Name of file containing a ticket-granting ticket (.kirbi or ccache) | |
| -TicketCache | <String> | Name of ticket cache file | |
| -Tickets | -Ticket | <String[]> | Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName | <UserPrincipalName> | User name to request TGT for U2U | |
| -UserCert | <String> | Name of file containing user’s certificate (for PKINIT) | |
| -UserKey | <String> | Name of file containing user’s key (for PKINIT) | |
| -UserKeyPassword | <String> | Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -NtlmVersion | <Version> | NTLM version number (a.b.c.d) | |
| -Workstation | -w | <String> | Name of workstation to send with NTLM authentication |
Client Behavior
| Name | Aliases | Value | Description |
|---|---|---|---|
| -DfsReferralBufferSize | <Int32> | Specifies the size for the DFS referral buffer (default=4096) | |
| -F, -FollowDfs | <SwitchParam> | Checks for and follows DFS referrals (default=true) |
Connection
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Dialects | <Smb2Dialect[]> | List of SMB2 dialects to negotiate | |
| Possible values: | |||
| Smb2_0_2 | |||
| Smb2_1 | |||
| Smb3_0 | |||
| Smb3_0_2 | |||
| Smb3_1_1 | |||
| -EncryptSmb | <SwitchParam> | Requires an encrypted connection | |
| -HostAddress | -ha | <String[]> | Network address(es) of the server |
| -RequireSecureNegotiate | <SwitchParam> | Requires the client to authenticate the negotiation | |
| -RequireSigning | -signreq | <SwitchParam> | Requires packets to be signed |
| -UseTcp4Only | -4 | <SwitchParam> | Only use TCP over IPv4 endpoint |
| -UseTcp6Only | -6 | <SwitchParam> | Only use TCP over IPv6 endpoint |
Output
| Name | Aliases | Value | Description |
|---|---|---|---|
| -ConsoleLogFormat | -LogFormat | <LogFormat> | Sets the format of log messages written to the console |
| Default: 0 | |||
| Possible values: | |||
| Text | |||
| TextWithTimestamp | |||
| Json | |||
| -DebugLog | -vvv | <SwitchParam> | Prints debug messages |
| -Diagnostic | -vv | <SwitchParam> | Prints diagnostic messages |
| -HumanReadable | <SwitchParam> | Formats file sizes as human-readable values | |
| -LogLevel | <LogMessageSeverity> | Sets the lowest level of messages to log | |
| Possible values: | |||
| Debug | |||
| Diagnostic | |||
| Verbose | |||
| Info | |||
| Warning | |||
| Error | |||
| Critical | |||
| -Verbose | -V | <SwitchParam> | Prints verbose messages |
Details
You may specify an alias either as a name, decimal RID, or hex RID prefixed with 0x. You may specify multiple aliases.
Examples
Example 1 - Look up administrators
LUMON-FS1 -UserName LUMON\milchick -Password Br3@kr00m! -EncryptRpc 544
Example 2 - Look up multiple aliases
LUMON-FS1 -UserName LUMON\milchick -Password Br3@kr00m! -EncryptRpc Administrators, "Backup Operators"
Example 3 - Look up bad alias
LUMON-FS1 -UserName LUMON\milchick -Password Br3@kr00m! -EncryptRpc Administrators, "Backup Operators"
Sam enumaliases
Enumerates aliases
Synopsis
Sam enumaliases [options] <ServerName>
Parameters
| Name | Aliases | Value | Description |
|---|---|---|---|
| <ServerName> | <String> | RPC server to interact with |
Options
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AuthEpm | <SwitchParam> | Authenticates EP mapper requests | |
| -AuthProxy | <EndPoint> | Endpoint of auth proxy | |
| -ConsoleOutputStyle | -OutputStyle | <OutputStyle> | Determines the output style |
| Possible values: | |||
| Freeform | |||
| Raw | |||
| Table | |||
| List | |||
| Csv | |||
| Tsv | |||
| Json | |||
| TreeTable | |||
| -ContinueOnError | <SwitchParam> | Continue even if errors occur | |
| Default: True | |||
| -Delegate | <SwitchParam> | Requests delegation (sends TGT and key for Kerberos) | |
| -EncryptEpm | <SwitchParam> | Encrypts EP mappend requests | |
| -EncryptRpc | <SwitchParam> | Encrypts RPC messages | |
| -OutputFields | <String[]> | Fields to display in output | |
| Possible values: | |||
| AccountName | |||
| Domain | |||
| AccountType | |||
| Id | |||
| Sid | |||
| MemberCount | |||
| AdminComment | |||
| -OutputHeaders | <SwitchParam> | Print headers for table/list/CSV/TSV styles | |
| Default: True | |||
| -PreferSmb | <SwitchParam> | If the interface supports named pipes, attempt to connect over the named pipe instead of TCP | |
| -RpcCallTimeout | <Duration> | Time to wait for RPC calls | |
| -RpcConnectTimeout | <Duration> | Time to wait for RPC connections | |
| -Socks5 | <host-or-ip:port> | End point of SOCKS 5 server to use | |
| -Spnego | <SwitchParam> | Uses SP-NEGO for authentication | |
| -SpnOverride | <SpnMapping[]> | Specifies an SPN override |
Authentication
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Anonymous | <SwitchParam> | Uses anonymous login | |
| -NtlmHash | <hexadecimal hash> | NTLM hash for NTLM authentication | |
| -Password | -p | <String> | Password to authenticate with |
| -UserDomain | -ud | <String> | Domain of user to authenticate with |
| -UserName | -u | <UserPrincipalName> | User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AesKey | <HexString> | AES key (128 or 256) | |
| -DelegateTicket | <String[]> | Sends the tickets (and keys) to the target for delegation | |
| -DesKey | <HexString> | DES key | |
| -Kdc | <host-or-ip:port> | KDC endpoint | |
| -Keytab | <String> | Name of keytab file | |
| -S4ProxyService | <SecurityPrincipalName> | Name of service to proxy through | |
| -S4UserCert | <String> | Name of file containing a certificate of a user to impersonate with S4U | |
| -S4UserName | <UserPrincipalName> | Name of user to impersonate with S4U | |
| -Tgt | <String> | Name of file containing a ticket-granting ticket (.kirbi or ccache) | |
| -TicketCache | <String> | Name of ticket cache file | |
| -Tickets | -Ticket | <String[]> | Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName | <UserPrincipalName> | User name to request TGT for U2U | |
| -UserCert | <String> | Name of file containing user’s certificate (for PKINIT) | |
| -UserKey | <String> | Name of file containing user’s key (for PKINIT) | |
| -UserKeyPassword | <String> | Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -NtlmVersion | <Version> | NTLM version number (a.b.c.d) | |
| -Workstation | -w | <String> | Name of workstation to send with NTLM authentication |
Client Behavior
| Name | Aliases | Value | Description |
|---|---|---|---|
| -DfsReferralBufferSize | <Int32> | Specifies the size for the DFS referral buffer (default=4096) | |
| -F, -FollowDfs | <SwitchParam> | Checks for and follows DFS referrals (default=true) |
Connection
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Dialects | <Smb2Dialect[]> | List of SMB2 dialects to negotiate | |
| Possible values: | |||
| Smb2_0_2 | |||
| Smb2_1 | |||
| Smb3_0 | |||
| Smb3_0_2 | |||
| Smb3_1_1 | |||
| -EncryptSmb | <SwitchParam> | Requires an encrypted connection | |
| -HostAddress | -ha | <String[]> | Network address(es) of the server |
| -RequireSecureNegotiate | <SwitchParam> | Requires the client to authenticate the negotiation | |
| -RequireSigning | -signreq | <SwitchParam> | Requires packets to be signed |
| -UseTcp4Only | -4 | <SwitchParam> | Only use TCP over IPv4 endpoint |
| -UseTcp6Only | -6 | <SwitchParam> | Only use TCP over IPv6 endpoint |
Output
| Name | Aliases | Value | Description |
|---|---|---|---|
| -ConsoleLogFormat | -LogFormat | <LogFormat> | Sets the format of log messages written to the console |
| Default: 0 | |||
| Possible values: | |||
| Text | |||
| TextWithTimestamp | |||
| Json | |||
| -DebugLog | -vvv | <SwitchParam> | Prints debug messages |
| -Diagnostic | -vv | <SwitchParam> | Prints diagnostic messages |
| -HumanReadable | <SwitchParam> | Formats file sizes as human-readable values | |
| -LogLevel | <LogMessageSeverity> | Sets the lowest level of messages to log | |
| Possible values: | |||
| Debug | |||
| Diagnostic | |||
| Verbose | |||
| Info | |||
| Warning | |||
| Error | |||
| Critical | |||
| -Verbose | -V | <SwitchParam> | Prints verbose messages |
Details
Sam enumaliases attempts to query the general info and attributes for the groups returned by the server.
Examples
Example 1 - Enumerate all aliases
Sam enumaliases LUMON-FS1 -UserName milchick -Password Br3@kr00m!
Sam enumgroups
Enumerates groups
Synopsis
Sam enumgroups [options] <ServerName>
Parameters
| Name | Aliases | Value | Description |
|---|---|---|---|
| <ServerName> | <String> | RPC server to interact with |
Options
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AuthEpm | <SwitchParam> | Authenticates EP mapper requests | |
| -AuthProxy | <EndPoint> | Endpoint of auth proxy | |
| -ConsoleOutputStyle | -OutputStyle | <OutputStyle> | Determines the output style |
| Possible values: | |||
| Freeform | |||
| Raw | |||
| Table | |||
| List | |||
| Csv | |||
| Tsv | |||
| Json | |||
| TreeTable | |||
| -ContinueOnError | <SwitchParam> | Continue even if errors occur | |
| Default: True | |||
| -Delegate | <SwitchParam> | Requests delegation (sends TGT and key for Kerberos) | |
| -EncryptEpm | <SwitchParam> | Encrypts EP mappend requests | |
| -EncryptRpc | <SwitchParam> | Encrypts RPC messages | |
| -OutputFields | <String[]> | Fields to display in output | |
| Possible values: | |||
| AccountName | |||
| Domain | |||
| AccountType | |||
| Id | |||
| Sid | |||
| Attributes | |||
| MemberCount | |||
| AdminComment | |||
| -OutputHeaders | <SwitchParam> | Print headers for table/list/CSV/TSV styles | |
| Default: True | |||
| -PreferSmb | <SwitchParam> | If the interface supports named pipes, attempt to connect over the named pipe instead of TCP | |
| -RpcCallTimeout | <Duration> | Time to wait for RPC calls | |
| -RpcConnectTimeout | <Duration> | Time to wait for RPC connections | |
| -Socks5 | <host-or-ip:port> | End point of SOCKS 5 server to use | |
| -Spnego | <SwitchParam> | Uses SP-NEGO for authentication | |
| -SpnOverride | <SpnMapping[]> | Specifies an SPN override |
Authentication
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Anonymous | <SwitchParam> | Uses anonymous login | |
| -NtlmHash | <hexadecimal hash> | NTLM hash for NTLM authentication | |
| -Password | -p | <String> | Password to authenticate with |
| -UserDomain | -ud | <String> | Domain of user to authenticate with |
| -UserName | -u | <UserPrincipalName> | User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AesKey | <HexString> | AES key (128 or 256) | |
| -DelegateTicket | <String[]> | Sends the tickets (and keys) to the target for delegation | |
| -DesKey | <HexString> | DES key | |
| -Kdc | <host-or-ip:port> | KDC endpoint | |
| -Keytab | <String> | Name of keytab file | |
| -S4ProxyService | <SecurityPrincipalName> | Name of service to proxy through | |
| -S4UserCert | <String> | Name of file containing a certificate of a user to impersonate with S4U | |
| -S4UserName | <UserPrincipalName> | Name of user to impersonate with S4U | |
| -Tgt | <String> | Name of file containing a ticket-granting ticket (.kirbi or ccache) | |
| -TicketCache | <String> | Name of ticket cache file | |
| -Tickets | -Ticket | <String[]> | Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName | <UserPrincipalName> | User name to request TGT for U2U | |
| -UserCert | <String> | Name of file containing user’s certificate (for PKINIT) | |
| -UserKey | <String> | Name of file containing user’s key (for PKINIT) | |
| -UserKeyPassword | <String> | Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -NtlmVersion | <Version> | NTLM version number (a.b.c.d) | |
| -Workstation | -w | <String> | Name of workstation to send with NTLM authentication |
Client Behavior
| Name | Aliases | Value | Description |
|---|---|---|---|
| -DfsReferralBufferSize | <Int32> | Specifies the size for the DFS referral buffer (default=4096) | |
| -F, -FollowDfs | <SwitchParam> | Checks for and follows DFS referrals (default=true) |
Connection
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Dialects | <Smb2Dialect[]> | List of SMB2 dialects to negotiate | |
| Possible values: | |||
| Smb2_0_2 | |||
| Smb2_1 | |||
| Smb3_0 | |||
| Smb3_0_2 | |||
| Smb3_1_1 | |||
| -EncryptSmb | <SwitchParam> | Requires an encrypted connection | |
| -HostAddress | -ha | <String[]> | Network address(es) of the server |
| -RequireSecureNegotiate | <SwitchParam> | Requires the client to authenticate the negotiation | |
| -RequireSigning | -signreq | <SwitchParam> | Requires packets to be signed |
| -UseTcp4Only | -4 | <SwitchParam> | Only use TCP over IPv4 endpoint |
| -UseTcp6Only | -6 | <SwitchParam> | Only use TCP over IPv6 endpoint |
Output
| Name | Aliases | Value | Description |
|---|---|---|---|
| -ConsoleLogFormat | -LogFormat | <LogFormat> | Sets the format of log messages written to the console |
| Default: 0 | |||
| Possible values: | |||
| Text | |||
| TextWithTimestamp | |||
| Json | |||
| -DebugLog | -vvv | <SwitchParam> | Prints debug messages |
| -Diagnostic | -vv | <SwitchParam> | Prints diagnostic messages |
| -HumanReadable | <SwitchParam> | Formats file sizes as human-readable values | |
| -LogLevel | <LogMessageSeverity> | Sets the lowest level of messages to log | |
| Possible values: | |||
| Debug | |||
| Diagnostic | |||
| Verbose | |||
| Info | |||
| Warning | |||
| Error | |||
| Critical | |||
| -Verbose | -V | <SwitchParam> | Prints verbose messages |
Details
Sam enumgroups attempts to query the general info for the groups returned by the server.
Examples
Example 1 - Enumerate all groups
Sam enumgroups LUMON-DC1 -UserName milchick -Password Br3@kr00m!
Sam enumusers
Enumerates user accounts
Synopsis
Sam enumusers [options] <ServerName>
Parameters
| Name | Aliases | Value | Description |
|---|---|---|---|
| <ServerName> | <String> | RPC server to interact with |
Options
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AuthEpm | <SwitchParam> | Authenticates EP mapper requests | |
| -AuthProxy | <EndPoint> | Endpoint of auth proxy | |
| -ConsoleOutputStyle | -OutputStyle | <OutputStyle> | Determines the output style |
| Possible values: | |||
| Freeform | |||
| Raw | |||
| Table | |||
| List | |||
| Csv | |||
| Tsv | |||
| Json | |||
| TreeTable | |||
| -ContinueOnError | <SwitchParam> | Continue even if errors occur | |
| Default: True | |||
| -Delegate | <SwitchParam> | Requests delegation (sends TGT and key for Kerberos) | |
| -EncryptEpm | <SwitchParam> | Encrypts EP mappend requests | |
| -EncryptRpc | <SwitchParam> | Encrypts RPC messages | |
| -OutputFields | <String[]> | Fields to display in output | |
| Possible values: | |||
| AccountName | |||
| Domain | |||
| AccountType | |||
| Id | |||
| Sid | |||
| FullName | |||
| AdminComment | |||
| PasswordLastSet | |||
| LastLogon | |||
| BadPasswordCount | |||
| -OutputHeaders | <SwitchParam> | Print headers for table/list/CSV/TSV styles | |
| Default: True | |||
| -PreferSmb | <SwitchParam> | If the interface supports named pipes, attempt to connect over the named pipe instead of TCP | |
| -RpcCallTimeout | <Duration> | Time to wait for RPC calls | |
| -RpcConnectTimeout | <Duration> | Time to wait for RPC connections | |
| -Socks5 | <host-or-ip:port> | End point of SOCKS 5 server to use | |
| -Spnego | <SwitchParam> | Uses SP-NEGO for authentication | |
| -SpnOverride | <SpnMapping[]> | Specifies an SPN override |
Authentication
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Anonymous | <SwitchParam> | Uses anonymous login | |
| -NtlmHash | <hexadecimal hash> | NTLM hash for NTLM authentication | |
| -Password | -p | <String> | Password to authenticate with |
| -UserDomain | -ud | <String> | Domain of user to authenticate with |
| -UserName | -u | <UserPrincipalName> | User name to authenticate with, not including the domain |
Authentication (Kerberos)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -AesKey | <HexString> | AES key (128 or 256) | |
| -DelegateTicket | <String[]> | Sends the tickets (and keys) to the target for delegation | |
| -DesKey | <HexString> | DES key | |
| -Kdc | <host-or-ip:port> | KDC endpoint | |
| -Keytab | <String> | Name of keytab file | |
| -S4ProxyService | <SecurityPrincipalName> | Name of service to proxy through | |
| -S4UserCert | <String> | Name of file containing a certificate of a user to impersonate with S4U | |
| -S4UserName | <UserPrincipalName> | Name of user to impersonate with S4U | |
| -Tgt | <String> | Name of file containing a ticket-granting ticket (.kirbi or ccache) | |
| -TicketCache | <String> | Name of ticket cache file | |
| -Tickets | -Ticket | <String[]> | Name of file containing service tickets (.kirbi or ccache) |
| -U2UserName | <UserPrincipalName> | User name to request TGT for U2U | |
| -UserCert | <String> | Name of file containing user’s certificate (for PKINIT) | |
| -UserKey | <String> | Name of file containing user’s key (for PKINIT) | |
| -UserKeyPassword | <String> | Password to decrypt file containing user’s key (for PKINIT) |
Authentication (NTLM)
| Name | Aliases | Value | Description |
|---|---|---|---|
| -NtlmVersion | <Version> | NTLM version number (a.b.c.d) | |
| -Workstation | -w | <String> | Name of workstation to send with NTLM authentication |
Client Behavior
| Name | Aliases | Value | Description |
|---|---|---|---|
| -DfsReferralBufferSize | <Int32> | Specifies the size for the DFS referral buffer (default=4096) | |
| -F, -FollowDfs | <SwitchParam> | Checks for and follows DFS referrals (default=true) |
Connection
| Name | Aliases | Value | Description |
|---|---|---|---|
| -Dialects | <Smb2Dialect[]> | List of SMB2 dialects to negotiate | |
| Possible values: | |||
| Smb2_0_2 | |||
| Smb2_1 | |||
| Smb3_0 | |||
| Smb3_0_2 | |||
| Smb3_1_1 | |||
| -EncryptSmb | <SwitchParam> | Requires an encrypted connection | |
| -HostAddress | -ha | <String[]> | Network address(es) of the server |
| -RequireSecureNegotiate | <SwitchParam> | Requires the client to authenticate the negotiation | |
| -RequireSigning | -signreq | <SwitchParam> | Requires packets to be signed |
| -UseTcp4Only | -4 | <SwitchParam> | Only use TCP over IPv4 endpoint |
| -UseTcp6Only | -6 | <SwitchParam> | Only use TCP over IPv6 endpoint |
Output
| Name | Aliases | Value | Description |
|---|---|---|---|
| -ConsoleLogFormat | -LogFormat | <LogFormat> | Sets the format of log messages written to the console |
| Default: 0 | |||
| Possible values: | |||
| Text | |||
| TextWithTimestamp | |||
| Json | |||
| -DebugLog | -vvv | <SwitchParam> | Prints debug messages |
| -Diagnostic | -vv | <SwitchParam> | Prints diagnostic messages |
| -HumanReadable | <SwitchParam> | Formats file sizes as human-readable values | |
| -LogLevel | <LogMessageSeverity> | Sets the lowest level of messages to log | |
| Possible values: | |||
| Debug | |||
| Diagnostic | |||
| Verbose | |||
| Info | |||
| Warning | |||
| Error | |||
| Critical | |||
| -Verbose | -V | <SwitchParam> | Prints verbose messages |
Details
Sam enumusers attempts to query the general and account info for the users returned by the server.
Examples
Example 1 - Enumerate all accounts
Sam enumusers LUMON-DC1 -UserName milchick -Password Br3@kr00m!