What Is NetBIOS Enumeration? Tools, Commands and How to Defend

NetBIOS enumeration is a critical ethical hacking technique used to identify shared folders, usernames, and system information in Windows networks. Learn how to perform NetBIOS enumeration using tools like nbtstat, net view, enum4linux, and Metasploit, along with examples, commands, and defense strategies.

Jun 19, 2025 - 14:14
Updated: 7 days ago
103.4k
What Is NetBIOS Enumeration? Tools, Commands and How to Defend

Quick answer: NetBIOS enumeration is the process of querying Windows hosts over NetBIOS (UDP 137, 138 and TCP 139) to list computer names, workgroups or domains, MAC addresses, logged-in users and shared folders. Testers use nbtstat, net view, nmap and nbtscan on authorised networks. Defenders disable NetBIOS over TCP/IP, block ports 137 to 139 and restrict anonymous access.

Key takeaways

  • NetBIOS provides name, datagram and session services on ports 137 (UDP), 138 (UDP) and 139 (TCP).
  • Enumeration reveals host names, domain or workgroup, MAC address, services and shares, which guide later testing.
  • Only do this on systems you own or have written permission to test, such as a lab VM.
  • Old null-session weaknesses are mostly closed on modern Windows, but misconfigured legacy systems still leak data.
  • Defence: turn off NetBIOS over TCP/IP where unneeded, block 137 to 139 at the perimeter, disable SMBv1 and restrict anonymous access.

What is NetBIOS enumeration?

NetBIOS (Network Basic Input/Output System) is an old Windows service that lets applications on different computers find each other and share resources on a local network. Enumeration means actively asking a host what it exposes. In a penetration test it is part of the information-gathering stage, after discovering live hosts and before testing specific services.

Authorisation first. Scanning or enumerating systems without written permission is illegal in India under the Information Technology Act, 2000. Practise only on your own lab machines or platforms built for training.

How does NetBIOS work?

ServicePortPurpose
Name serviceUDP 137Registers and resolves NetBIOS names
Datagram serviceUDP 138Connectionless messages and browsing
Session serviceTCP 139Connection-oriented sessions such as file sharing

Modern Windows also shares files with SMB directly on TCP 445, without NetBIOS. Many networks still run NetBIOS for compatibility, which is why the information leaks.

What can an attacker learn?

  • Computer names and their roles, such as file server or domain controller
  • Workgroup or domain name
  • MAC address of the network card
  • Logged-in user names and running services
  • Shared folders and printers

Which tools are used?

ToolWhat it doesPlatform
nbtstatShows NetBIOS name tables and statisticsWindows
net viewLists shared resourcesWindows
nbtscanScans a subnet for NetBIOS names and MACsLinux, Windows
NmapNetBIOS and SMB scriptsCross-platform
smbclient, enum4linuxQuery SMB shares and usersLinux

Commands in a lab

Use a Windows VM and a second machine on a host-only network. Replace the example address with your own lab VM.

nbtstat -A 192.168.56.10 # name table and MAC of a remote host
nbtstat -n # your own local name table
nbtstat -c # cache of resolved names
net view \\192.168.56.10 # shared resources on the host
nbtscan 192.168.56.0/24 # scan a lab subnet (Linux)
nmap -sU -p137 --script nbstat 192.168.56.10

A typical nbtstat -A result lists a table such as LAB-PC <00> UNIQUE Registered and WORKGROUP <00> GROUP Registered, followed by the MAC address. The hexadecimal suffix shows the service: <00> is the workstation name, <20> the file server service, and <03> the messenger or logged-in user entry. Names will differ on your system.

The Nmap nbstat script is documented in the Nmap reference guide. For wider enumeration, see our guides to enumeration techniques, what enumeration is and Nmap scripts.

What is a null session?

A null session is an unauthenticated connection to a Windows share used for administrative information. On old systems it could reveal user lists and share names. Windows has restricted anonymous access for years, so on a patched modern host the results are limited. Legacy servers, old appliances and misconfigured devices are where it still matters.

How to defend against NetBIOS enumeration

  1. Disable NetBIOS over TCP/IP on adapters that do not need it (network adapter, IPv4 advanced settings, WINS tab).
  2. Block UDP 137, 138 and TCP 139 at the perimeter and between network segments. Do not expose 445 to the internet.
  3. Disable SMBv1, and require SMB signing where possible.
  4. Restrict anonymous access with the relevant security policy settings, and use least-privilege share permissions.
  5. Turn on host firewalls and monitor for sweeps of ports 137 to 139 in logs or IDS alerts.
  6. Segment legacy systems that cannot be changed.

Common mistakes

  • Running a scan on a company or college network without a signed scope.
  • Assuming old null-session tricks still work on current Windows.
  • Blocking port 139 but leaving 445 and SMBv1 open.
  • Forgetting that NetBIOS name resolution can also be abused for spoofing on the local network.

Next steps

Next steps: for hands-on practice of enumeration in a legal lab, see our CEH v13 AI course.

Frequently Asked Questions

It is the process of querying Windows hosts over NetBIOS to collect computer names, domain or workgroup, MAC addresses, users and shares. Ethical hackers do it on authorised systems to find exposed information and misconfigurations.

NetBIOS uses UDP 137 for name service, UDP 138 for datagram service and TCP 139 for session service. File sharing over SMB can also run directly on TCP 445 without NetBIOS.

The nbtstat -A command takes an IP address and displays the remote host's NetBIOS name table and MAC address. It is a quick way to see names and services a machine registers. Use -a with a name instead.

Net view lists computers on a network or the shared resources on a specified host, such as net view \\192.168.56.10. Access depends on permissions, and modern systems often restrict anonymous queries.

Disable NetBIOS over TCP/IP where it is not needed, block ports 137 to 139 at firewalls, disable SMBv1, restrict anonymous access and monitor logs for sweeps. Segment legacy systems that must keep NetBIOS running.

Only with permission. Enumerating systems you do not own or lack written authorisation for can break the Information Technology Act, 2000 in India. Practise in your own lab or a legal training platform.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.