Windows Gather Local Admin Search

This module will identify systems in a given range that the supplied domain user (should migrate into a user pid) has administrative access to by using the Windows API OpenSCManagerA to establishing a handle to the remote host. Additionally it can enumerate logged in users and group membership via Windows API NetWkstaUserEnum and NetUserGetGroups.

  • Brandon McCann "zeknox" <bmccann [at]>
  • Thomas McCarthy "smilingraccoon" <smilingraccoon [at]>
  • Royce Davis "r3dy" <rdavis [at]>


  • windows



Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use post/windows/gather/local_admin_search_enum msf post(local_admin_search_enum) > sessions ...sessions... msf post(local_admin_search_enum) > set SESSION <session-id> msf post(local_admin_search_enum) > show options and set options... msf post(local_admin_search_enum) > run