Use os scripts nmap + nmap: link
"sudo nmap -sU -sS --script smb-enum-shares.nse -p U:137,T:139 "
Ou empilhe as opções:
nmap -v -sU -sS --min-hostgroup 50 --script=smb-os-discovery --script=smbv2-enabled --script=smb-enum-domains --script=smb-enum-groups --script=smb-enum-processes --script=smb-enum-sessions --script=smb-enum-users --script=smb-security-mode --script=smb-server-stats --script=smb-system-info -p 137,139,445 -oA nmap.smb.scripts.scan.results 10.10.10.10/24
Lista de todos os scripts do nmap: link