Password Policies
FROM LINUX
CrackMapExec:
With valid domain credentials, the password policy can be obtained remotely using tools like CrackMapExec
or rpcclient
.
SMB NULL Sessions
An SMB NULL session may allow an attacker to retrieve domain information without authentication.