Name
rpcclient commands
Synopsis
Aside from a few miscellaneous commands, the rpclient commands fall into three groups: LSARPC, SAMR, and SPOOLSS. The function names mentioned in some of the commands are those documented in the Microsoft Platform SDK.
General commands
-
debuglevellevel Sets the debugging level to
level. With no argument, the current debugging level is printed.-
help Prints help on the commands.
-
quit Exits rpcclient. A synonym is
exit.
Local Security Authority Remote Procedure Calls (LSARPC) commands
-
enumprivs Lists the types of privileges known to this domain.
-
enumtrust Lists the domains trusted by this domain.
-
getdispnamepriv_name Prints information on the privilege named
priv_name.-
lookupsidsname Finds a name that corresponds to a security identifier (SID).
-
lookupnamessid Finds the SID for one or more names.
-
lsaquery Queries the LSA object.
-
lsaenumsid Lists SIDs for the local LSA.
-
lsaquerysecobj Prints information on security objects for the LSA.
Security Access Manager RPC (SAMR) commands
-
createdomuserusername Adds a new user in the domain.
-
deletedomuserusername Removes a user from the domain.
-
enumalsgroupstype Lists alias groups in the domain, along with their group RIDs. The
typeargument can be eitherbuiltin, to list Windows built-in groups such asAdministratorsandPowerUsers, ordomain, to list groups in the domain. See also the queryuseraliases command.-
enumdomgroups Lists the groups in the domain, along with their group RIDs.
-
queryaliasmemuser_rid
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access