> For the complete documentation index, see [llms.txt](https://pnpt.adot8.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://pnpt.adot8.com/active-directory/initial-attack-strategy/rpc.md).

# RPC

```
rpcclient -U '' -N 10.10.10.169  
```

```
enumdomusers
enumdomgroups
```

{% hint style="info" %}
Some bash kungfu  can be used to cleanup the users output: `cat raw | awk -F [ '{print $2}' | awk -F] '{print $1}' > users.txt`
{% endhint %}

```
queryuser joe
queryuser 0x451    
querygroup 0x44f        <-- Must use the RID for querying the group
querygroupmem 0x44f     <-- Shows what user is in the group(by rid)
```

```
querydispinfo        <-- Displays comments made on accounts
```
