Field kit

Command builder

Safe example recipes

Choose a target type and phase. Fill placeholders once, then copy ready-to-edit commands. Every recipe carries RoE warnings — examples are for authorized labs and networks you own.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Builder controls

Placeholders

23 recipes in library · showing 9

Reconnaissance
beginner

Home LAN host discovery

Inventory live hosts on a network you own: ARP/ping sweeps, neighbor tables, and a light service census before deeper scans.

RoE / safety

  • Only scan networks you own or have written authorization to test.
  • Avoid aggressive timing against cameras, bulbs, and other fragile IoT.
  • Document your scope (CIDR, excluded hosts) before you start.
ARP sweep (layer 2)arp-scan
sudo arp-scan --localnet

Best first pass when you are on the same L2 segment.

Ping discoveryNmap
nmap -sn 192.168.1.0/24 -oA home-discovery

Host discovery without port scanning.

Neighbor cache
ip neigh show

Corroborate with DHCP leases from the router UI.

Top ports censusNmap
nmap -sV --top-ports 100 192.168.1.0/24 -oA home-top100

Gentle service fingerprint; save all output formats.

Enumeration
beginner

Router admin surface check

Identify the gateway, probe common admin ports, grab HTTP titles/certs, and verify WAN management is off on equipment you administer.

RoE / safety

  • Default credentials and firmware exploits are for owned/lab gear only.
  • Never force auth against a neighbor or ISP-managed CPE without permission.
  • Prefer read-only recon; change passwords only on devices you manage.
Default gateway
ip route | grep default

Confirm the admin IP before scanning.

Admin ports + titlesNmap
nmap -sV -p 80,443,8080,8443,22,23,53 --script http-title,ssl-cert 192.168.1.50 -oA router-admin
HTTP fingerprintWhatWeb
whatweb http://192.168.1.50
Public IP (WAN exposure baseline)
curl -s https://api.ipify.org && echo

Pair with Shodan/ShieldsUP for your own public IP only.

Enumeration
beginner

Camera / IoT RTSP and admin enum

Map common camera ports (HTTP, RTSP, ONVIF), check for open streams on owned devices, and capture evidence for hardening.

RoE / safety

  • Only target cameras and IoT you own.
  • Do not brute-force cloud accounts or vendor portals.
  • Stop at proof-of-access; no stream recording of third-party spaces.
Camera port mapNmap
nmap -sV -p 80,443,554,8000,8080,8554,37777,34567 192.168.1.50 -oA camera-ports
HTTP title / serverNmap NSE Scripts
nmap -p 80,443,8080 --script http-title,http-headers 192.168.1.50
RTSP OPTIONS probeffuf
ffuf -u rtsp://192.168.1.50:554/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc all -t 5

Lab-owned cameras only; keep threads low.

mDNS IoT discovery
avahi-browse -a -r

Often reveals camera hostnames and services.

Scanning
beginner

Nmap staged scan workflow

Professional pacing: discover live hosts, top ports, full TCP, then version and script scans with saved artifacts.

RoE / safety

  • Aggressive scripts (-A, intrusive NSE) need explicit approval on production.
  • UDP scans are slow and noisy; justify them in scope notes.
  • Always save -oA output for the report evidence pack.
Stage 1 — discoveryNmap
nmap -sn 192.168.1.0/24 -oA stage1-discover
Stage 2 — top portsNmap
nmap -sS --top-ports 1000 -T4 192.168.1.50 -oA stage2-top
Stage 3 — full TCPNmap
nmap -sS -p- -T4 --min-rate 500 192.168.1.50 -oA stage3-full

Adjust rate for fragile targets.

Stage 4 — version + safe scriptsNmap
nmap -sV -sC -p $(grep -oP '\d+/open' stage3-full.gnmap | cut -d/ -f1 | tr '\n' ',') 192.168.1.50 -oA stage4-detail
Enumeration
beginner

SMB enumeration (lab)

List shares, permissions, and interesting files via SMB without escalating beyond authorized credentials.

RoE / safety

  • Null sessions and guest access can still be sensitive; document only.
  • Do not recursively download entire file shares without client approval.
  • Watch for ransomware-like mass access patterns that trip detections.
Nmap SMB scriptsNmap NSE Scripts
nmap -p 445 --script smb-enum-shares,smb-enum-users,smb-os-discovery 192.168.1.50
smbmapSMBMap
smbmap -H 192.168.1.50 -u 'labuser' -p 'LabPass1!' -d 'lab.local'
smbclient list
smbclient -L //192.168.1.50 -U 'lab.local/labuser%LabPass1!'
enum4linux-ng styleenum4linux-ng
enum4linux -a 192.168.1.50
Scanning
intermediate

Wireless assessment (owned AP only)

Survey and assess Wi-Fi you own: inventory SSIDs, check encryption, and verify WPS and guest isolation settings.

RoE / safety

  • Cracking or associating to networks you do not own is illegal.
  • Disable WPS and use WPA2/WPA3-Personal or Enterprise on home gear.
  • Deauth and handshake capture only on your own lab AP.
Monitor mode scanAircrack-ng Suite
sudo airmon-ng start eth0 && sudo airodump-ng eth0mon
Kismet surveyKismet
sudo kismet -c eth0
WPA handshake crack (owned AP)Aircrack-ng Suite
aircrack-ng -w /usr/share/seclists/Discovery/Web-Content/common.txt capture-01.cap

Only handshakes from APs you own.

Defense / hardening
beginner

Host hardening with UFW (Linux)

Apply a default-deny host firewall, allow only required services, and verify rules after changes.

RoE / safety

  • Misconfigured firewall rules can lock you out of remote systems — keep a console path.
  • Coordinate changes on production hosts with change control.
  • Firewall is one control; pair with updates, SSH keys, and least privilege.
Default policies
sudo ufw default deny incoming && sudo ufw default allow outgoing
Allow SSH (adjust port)
sudo ufw allow 22/tcp comment 'SSH'
Enable and status
sudo ufw enable && sudo ufw status verbose
Verify from scannerNmap
nmap -sS -p- 192.168.1.50 -oA post-ufw-check
Reconnaissance
beginner

Packet capture and protocol review

Capture traffic on an interface you control, filter for cleartext secrets and unexpected destinations, and document findings.

RoE / safety

  • Capturing traffic may include third-party personal data — minimize and redact.
  • Only capture on networks and hosts you are authorized to monitor.
  • Store pcaps encrypted; delete when no longer needed for the report.
tcpdump capturetcpdump
sudo tcpdump -i eth0 -w lab-capture.pcap host 192.168.1.50
Wireshark openWireshark / tshark
wireshark lab-capture.pcap
Useful display filtersWireshark / tshark
http.request || dns || tcp.port == 554 || tcp.contains "password"

Enter as Wireshark display filter; adjust for protocol.

Defense / hardening
beginner

Router WAN exposure cleanup

Verify remote admin, UPnP forwards, and open WAN ports on your own edge, then disable risky exposures.

RoE / safety

  • Only change settings on equipment you administer.
  • ISP-managed gateways may require their app or support for some settings.
  • Document before/after for your personal security notes.
LAN-side admin portsNmap
nmap -sV -p 80,443,22,23,8080 192.168.1.50
List UPnP mappings
upnpc -l

Remove unexpected port forwards in the router UI.

Public IP check
curl -s https://api.ipify.org && echo
External view (own IP)Shodan
shodan host YOUR.PUBLIC.IP

Replace with your public IP; free API limits apply.