What Is NetBIOS Enumeration? Tools, Commands and How to Defend
NetBIOS enumeration is a critical ethical hacking technique used to identify shared folders, usernames, and system information in Windows networks. Learn how to perform NetBIOS enumeration using tools like nbtstat, net view, enum4linux, and Metasploit, along with examples, commands, and defense strategies.
Quick answer: NetBIOS enumeration is the process of querying Windows hosts over NetBIOS (UDP 137, 138 and TCP 139) to list computer names, workgroups or domains, MAC addresses, logged-in users and shared folders. Testers use nbtstat, net view, nmap and nbtscan on authorised networks. Defenders disable NetBIOS over TCP/IP, block ports 137 to 139 and restrict anonymous access.
Key takeaways
- NetBIOS provides name, datagram and session services on ports 137 (UDP), 138 (UDP) and 139 (TCP).
- Enumeration reveals host names, domain or workgroup, MAC address, services and shares, which guide later testing.
- Only do this on systems you own or have written permission to test, such as a lab VM.
- Old null-session weaknesses are mostly closed on modern Windows, but misconfigured legacy systems still leak data.
- Defence: turn off NetBIOS over TCP/IP where unneeded, block 137 to 139 at the perimeter, disable SMBv1 and restrict anonymous access.
What is NetBIOS enumeration?
NetBIOS (Network Basic Input/Output System) is an old Windows service that lets applications on different computers find each other and share resources on a local network. Enumeration means actively asking a host what it exposes. In a penetration test it is part of the information-gathering stage, after discovering live hosts and before testing specific services.
Authorisation first. Scanning or enumerating systems without written permission is illegal in India under the Information Technology Act, 2000. Practise only on your own lab machines or platforms built for training.
How does NetBIOS work?
| Service | Port | Purpose |
|---|---|---|
| Name service | UDP 137 | Registers and resolves NetBIOS names |
| Datagram service | UDP 138 | Connectionless messages and browsing |
| Session service | TCP 139 | Connection-oriented sessions such as file sharing |
Modern Windows also shares files with SMB directly on TCP 445, without NetBIOS. Many networks still run NetBIOS for compatibility, which is why the information leaks.
What can an attacker learn?
- Computer names and their roles, such as file server or domain controller
- Workgroup or domain name
- MAC address of the network card
- Logged-in user names and running services
- Shared folders and printers
Which tools are used?
| Tool | What it does | Platform |
|---|---|---|
| nbtstat | Shows NetBIOS name tables and statistics | Windows |
| net view | Lists shared resources | Windows |
| nbtscan | Scans a subnet for NetBIOS names and MACs | Linux, Windows |
| Nmap | NetBIOS and SMB scripts | Cross-platform |
| smbclient, enum4linux | Query SMB shares and users | Linux |
Commands in a lab
Use a Windows VM and a second machine on a host-only network. Replace the example address with your own lab VM.
nbtstat -A 192.168.56.10 # name table and MAC of a remote host
nbtstat -n # your own local name table
nbtstat -c # cache of resolved names
net view \\192.168.56.10 # shared resources on the host
nbtscan 192.168.56.0/24 # scan a lab subnet (Linux)
nmap -sU -p137 --script nbstat 192.168.56.10
A typical nbtstat -A result lists a table such as LAB-PC <00> UNIQUE Registered and WORKGROUP <00> GROUP Registered, followed by the MAC address. The hexadecimal suffix shows the service: <00> is the workstation name, <20> the file server service, and <03> the messenger or logged-in user entry. Names will differ on your system.
The Nmap nbstat script is documented in the Nmap reference guide. For wider enumeration, see our guides to enumeration techniques, what enumeration is and Nmap scripts.
What is a null session?
A null session is an unauthenticated connection to a Windows share used for administrative information. On old systems it could reveal user lists and share names. Windows has restricted anonymous access for years, so on a patched modern host the results are limited. Legacy servers, old appliances and misconfigured devices are where it still matters.
How to defend against NetBIOS enumeration
- Disable NetBIOS over TCP/IP on adapters that do not need it (network adapter, IPv4 advanced settings, WINS tab).
- Block UDP 137, 138 and TCP 139 at the perimeter and between network segments. Do not expose 445 to the internet.
- Disable SMBv1, and require SMB signing where possible.
- Restrict anonymous access with the relevant security policy settings, and use least-privilege share permissions.
- Turn on host firewalls and monitor for sweeps of ports 137 to 139 in logs or IDS alerts.
- Segment legacy systems that cannot be changed.
Common mistakes
- Running a scan on a company or college network without a signed scope.
- Assuming old null-session tricks still work on current Windows.
- Blocking port 139 but leaving 445 and SMBv1 open.
- Forgetting that NetBIOS name resolution can also be abused for spoofing on the local network.
Next steps
Next steps: for hands-on practice of enumeration in a legal lab, see our CEH v13 AI course.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0