Command builder
Safe example recipes
Choose a target type and phase. Fill placeholders once, then copy ready-to-edit commands. Every recipe carries RoE warnings — examples are for authorized labs and networks you own.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Builder controls
Placeholders
23 recipes in library · showing 9
Home LAN host discovery
Inventory live hosts on a network you own: ARP/ping sweeps, neighbor tables, and a light service census before deeper scans.
RoE / safety
- Only scan networks you own or have written authorization to test.
- Avoid aggressive timing against cameras, bulbs, and other fragile IoT.
- Document your scope (CIDR, excluded hosts) before you start.
sudo arp-scan --localnet
Best first pass when you are on the same L2 segment.
ip neigh show
Corroborate with DHCP leases from the router UI.
nmap -sV --top-ports 100 192.168.1.0/24 -oA home-top100
Gentle service fingerprint; save all output formats.
Router admin surface check
Identify the gateway, probe common admin ports, grab HTTP titles/certs, and verify WAN management is off on equipment you administer.
RoE / safety
- Default credentials and firmware exploits are for owned/lab gear only.
- Never force auth against a neighbor or ISP-managed CPE without permission.
- Prefer read-only recon; change passwords only on devices you manage.
ip route | grep default
Confirm the admin IP before scanning.
nmap -sV -p 80,443,8080,8443,22,23,53 --script http-title,ssl-cert 192.168.1.50 -oA router-admin
whatweb http://192.168.1.50
curl -s https://api.ipify.org && echo
Pair with Shodan/ShieldsUP for your own public IP only.
Camera / IoT RTSP and admin enum
Map common camera ports (HTTP, RTSP, ONVIF), check for open streams on owned devices, and capture evidence for hardening.
RoE / safety
- Only target cameras and IoT you own.
- Do not brute-force cloud accounts or vendor portals.
- Stop at proof-of-access; no stream recording of third-party spaces.
nmap -sV -p 80,443,554,8000,8080,8554,37777,34567 192.168.1.50 -oA camera-ports
nmap -p 80,443,8080 --script http-title,http-headers 192.168.1.50
ffuf -u rtsp://192.168.1.50:554/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc all -t 5
Lab-owned cameras only; keep threads low.
avahi-browse -a -r
Often reveals camera hostnames and services.
Nmap staged scan workflow
Professional pacing: discover live hosts, top ports, full TCP, then version and script scans with saved artifacts.
RoE / safety
- Aggressive scripts (-A, intrusive NSE) need explicit approval on production.
- UDP scans are slow and noisy; justify them in scope notes.
- Always save -oA output for the report evidence pack.
nmap -sn 192.168.1.0/24 -oA stage1-discover
nmap -sS --top-ports 1000 -T4 192.168.1.50 -oA stage2-top
nmap -sS -p- -T4 --min-rate 500 192.168.1.50 -oA stage3-full
Adjust rate for fragile targets.
nmap -sV -sC -p $(grep -oP '\d+/open' stage3-full.gnmap | cut -d/ -f1 | tr '\n' ',') 192.168.1.50 -oA stage4-detail
SMB enumeration (lab)
List shares, permissions, and interesting files via SMB without escalating beyond authorized credentials.
RoE / safety
- Null sessions and guest access can still be sensitive; document only.
- Do not recursively download entire file shares without client approval.
- Watch for ransomware-like mass access patterns that trip detections.
nmap -p 445 --script smb-enum-shares,smb-enum-users,smb-os-discovery 192.168.1.50
smbmap -H 192.168.1.50 -u 'labuser' -p 'LabPass1!' -d 'lab.local'
smbclient -L //192.168.1.50 -U 'lab.local/labuser%LabPass1!'
enum4linux -a 192.168.1.50
Wireless assessment (owned AP only)
Survey and assess Wi-Fi you own: inventory SSIDs, check encryption, and verify WPS and guest isolation settings.
RoE / safety
- Cracking or associating to networks you do not own is illegal.
- Disable WPS and use WPA2/WPA3-Personal or Enterprise on home gear.
- Deauth and handshake capture only on your own lab AP.
sudo airmon-ng start eth0 && sudo airodump-ng eth0mon
sudo kismet -c eth0
aircrack-ng -w /usr/share/seclists/Discovery/Web-Content/common.txt capture-01.cap
Only handshakes from APs you own.
Host hardening with UFW (Linux)
Apply a default-deny host firewall, allow only required services, and verify rules after changes.
RoE / safety
- Misconfigured firewall rules can lock you out of remote systems — keep a console path.
- Coordinate changes on production hosts with change control.
- Firewall is one control; pair with updates, SSH keys, and least privilege.
sudo ufw default deny incoming && sudo ufw default allow outgoing
sudo ufw allow 22/tcp comment 'SSH'
sudo ufw enable && sudo ufw status verbose
nmap -sS -p- 192.168.1.50 -oA post-ufw-check
Packet capture and protocol review
Capture traffic on an interface you control, filter for cleartext secrets and unexpected destinations, and document findings.
RoE / safety
- Capturing traffic may include third-party personal data — minimize and redact.
- Only capture on networks and hosts you are authorized to monitor.
- Store pcaps encrypted; delete when no longer needed for the report.
sudo tcpdump -i eth0 -w lab-capture.pcap host 192.168.1.50
wireshark lab-capture.pcap
http.request || dns || tcp.port == 554 || tcp.contains "password"
Enter as Wireshark display filter; adjust for protocol.
Router WAN exposure cleanup
Verify remote admin, UPnP forwards, and open WAN ports on your own edge, then disable risky exposures.
RoE / safety
- Only change settings on equipment you administer.
- ISP-managed gateways may require their app or support for some settings.
- Document before/after for your personal security notes.
nmap -sV -p 80,443,22,23,8080 192.168.1.50
upnpc -l
Remove unexpected port forwards in the router UI.
curl -s https://api.ipify.org && echo
shodan host YOUR.PUBLIC.IP
Replace with your public IP; free API limits apply.