All modules

Module 04 · Operator

Scanning & Enumeration

Host discovery, port scanning, service enumeration, and the discipline of turning scan spam into a prioritized target list — always within written authorization.

2 lessons
12 deep sections
~135 min guided
Progress…

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Outcomes

  • Run staged Nmap workflows (discover → common ports → full → scripts)
  • Enumerate SMB, HTTP, DNS, and other common services with intent
  • Prioritize attack paths from evidence, not vibes
  • Export and parse scan artifacts for notes and reports
  • Balance speed tools with depth tools without losing methodology

Lessons

Lesson 1
65 min6 sections

Nmap staged methodology

Stop one-lining -A on entire subnets. Scan like a professional: stages, exports, timing, and intentional NSE — only on authorized targets.

Learning objectives

  • Choose scan types appropriate to network position and engagement goals
  • Execute a four-stage methodology and explain what each stage answers
  • Export -oA outputs and parse them into inventory tables
  • Use NSE scripts intentionally rather than as a blind default
  • Combine speed scanners with Nmap depth without abandoning scope discipline

Deep teach-through

Authorization, noise, and professional scanning

Port scanning without permission can be illegal or policy-violating depending on jurisdiction and context. In this academy you scan lab targets, machines you own, and client assets only under written Rules of Engagement. Bug bounty policies often restrict or ban scanning — read them.

Scanning is noisy. Expect IDS/IPS, SOC tickets, and rate limiting on production. Professionals schedule windows when required, throttle timing (-T and --max-rate), and coordinate with blue teams on collaborative tests. “I ran -T5 -A on the whole /16 at noon” is not expert behavior.

Keep the scope file as the only input to mass scanning. Discoveries that fall outside scope are inventory questions, not free ports to map. Log start time, source IP, and command line for every significant scan.

Stage 1–2: discovery and common ports

Stage 1 — host discovery: determine which addresses appear live from your vantage point. Techniques vary (ICMP, ARP on LAN, TCP probes to 80/443). On hostile or filtered networks, discovery may under-count; document limitations instead of inventing certainty.

Stage 2 — common ports on live hosts: top TCP ports (and UDP when justified) give quick attack surface without full 65535 costs. Many compromises start on a handful of services. Save output with -oA scans/stage2-common.

Avoid the beginner trap of full port + version + scripts + OS detect on every host at once. You waste time, generate noise, and often get incomplete results when the scan is interrupted. Stages create checkpoints and cleaner notes.

Stage 3–4: full ports, versions, and scripts

Stage 3 — full TCP (and selected UDP) on high-value hosts: once prioritization is clear, expand port coverage on VIP targets (domain controllers, jump boxes, app servers, anything with odd banners). Full scans take time; run them where they matter.

Stage 4 — version detection and NSE: -sV and carefully chosen scripts enrich inventory (http titles, smb capabilities, ssl-cert names). Prefer script categories and specific scripts over shotgun -A when you need control. Read what a script does before running it — some are intrusive.

OS detection is optional context, not truth from God. Treat it as a hint. Correlate with banners, HTTP stack, and domain role instead of betting the engagement on a single OS guess.

Scan types, timing, and middleboxes

SYN scan (-sS) is a common privileged default; connect scan (-sT) works without raw sockets but is louder at the application layer. UDP (-sU) is slow and ambiguous — use for known valuable UDP services (DNS, SNMP, VPN) rather than blind full UDP by default.

Timing templates (-T0..-T5) and rate controls trade speed for stealth and reliability. Production and WAN paths often need slower settings; labs can be faster. Packet loss and firewalls create false “filtered” results — retry and change probes before declaring hosts empty.

From different vantage points (internet vs VPN vs LAN) the same host may look different. Record vantage point in notes. If the client cares about external exposure, an internal-only open port is a different finding class than a WAN-exposed one.

Speed tools vs depth tools

Masscan, RustScan, and similar tools excel at quickly finding open ports across large authorized ranges. They are not a full replacement for Nmap’s version detection, scripting, and nuanced output. Typical pattern: speed tool for candidates → Nmap for depth on confirmed ports/hosts.

AutoRecon and similar wrappers chain enumeration once ports are known. Use them to accelerate labs and consistent coverage, but still understand each underlying command. If you cannot explain what AutoRecon ran, you cannot defend it in a report or client call.

Parse everything into structured notes: host, port, service, version, script highlights, priority. Greppable (-oG) and XML (-oX) outputs feed tooling; normal (-oN) feeds humans. -oA gives you all three — make it habit.

From scan spam to prioritization

Not every open port is equal. Internet-exposed RDP, databases, admin panels, and SMB often outrank a closed-looking host with only filtered noise. Internal AD estates prioritize DC ports, auth services, and attack paths over random printers — unless the printer is the path.

Build a simple priority matrix: exposure (external/internal), sensitivity (auth, data, admin), exploitability hints (version age, default creds likely), and business context from the client. This matrix drives where enumeration time goes next.

When scans fail or look empty, debug methodically: wrong VPN, wrong interface, ICMP-only filtering, IPv6-only service, rate limiting. Experts spend time validating negatives; beginners assume “nothing there” and miss the engagement.

Key concepts

Staged scanning
Progressive methodology that discovers, samples ports, expands on VIPs, then enriches with versions/scripts.
SYN scan
Half-open TCP probing that classifies ports without completing a full connect (typically needs privileges).
-oA output
Nmap switch writing normal, XML, and greppable results together for evidence and parsing.
NSE
Nmap Scripting Engine — optional scripts for discovery, enrichment, and (carefully) vulnerability checks.
Intrusive script
NSE or scanner check that may change state, crash a service, or generate high noise — requires explicit approval.

Common mistakes

  • nmap -A on entire subnets as the first and only command
  • No -oA, then losing results when the terminal scrolls away
  • Using -T5 against production without RoE and monitoring awareness
  • Running intrusive vuln scripts because they “might find something”
  • Trusting a single empty scan as proof nothing is exposed
  • Scanning IPs that appeared in reverse DNS but are out of scope

Defender view

  • Port scans are highly visible; network detection content often keys on them.
  • Exposure management (close unused ports, require VPN) beats arguing about scan ethics after a breach.
  • Allowlists and jump hosts reduce the external scan surface dramatically.

Operator checklist

  • Written authorization covers this range and time window
  • Stage 1–2 complete before full-port obsession on every host
  • All major scans saved with -oA under scans/
  • Timing/rate appropriate to environment (lab vs production)
  • Priority hosts listed before deep NSE and enum rabbit holes

Example commands & patterns

# LAB / AUTHORIZED TARGETS ONLY
sudo nmap -sn -iL scope.txt -oA scans/01-discover
sudo nmap -sS --top-ports 1000 -iL live-hosts.txt -oA scans/02-topports
sudo nmap -sS -p- --min-rate 500 vip-hosts.txt -oA scans/03-fulltcp
sudo nmap -sV -sC -p 22,80,443,445 192.168.56.10 -oA scans/04-version
sudo nmap -sV -p 445 --script smb-enum-shares,smb-os-discovery 192.168.56.10
sudo masscan -p1-65535 192.168.56.0/24 --rate 1000 -oL scans/masscan.lst
rustscan -a 192.168.56.10 -- -sV -sC -oA scans/rust-depth

Practice drills

  1. Scan Metasploitable (or similar lab host) with a staged approach and write a service inventory table
  2. Use at least two NSE scripts relevant to open ports found and note whether each is safe/intrusive
  3. Export -oA and open the XML/greppable outputs; extract open ports with a small script or one-liner
  4. Compare a top-ports scan vs full-port scan on one lab host; document what stage 3 uniquely found
  5. Write the exact command line and RoE note you would use for a slower production-safe common-port scan

Next: Enumerate high-value services with protocol-specific checklists and careful credential handling.

Lesson 2
70 min6 sections

Service-specific enumeration

What to do when you see 22, 80/443, 445, 3389, 389, 5432… — per-service playbooks, lockout awareness, and signal vs noise.

Learning objectives

  • Apply per-service enumeration checklists for common ports
  • Avoid credential lockouts and reckless password spraying
  • Distinguish “interesting” findings from background noise
  • Fingerprint web stacks and discover content without abandoning methodology
  • Document enum results so exploitation (later modules) starts from evidence

Deep teach-through

Enumeration as structured curiosity

Scanning tells you what is open; enumeration tells you what it is, how it is configured, and whether it smells like a path. Experts follow checklists per protocol so fatigue does not skip basics. Beginners click random exploits from search engines and get nowhere — or get banned from a program.

Always work from authorization and proportionality. Unauthenticated enum first when possible. Authenticated enum only with provided or legitimately obtained credentials for the engagement. Never spray passwords against production without explicit RoE language and rate limits.

Notes structure: for each host:port, record banner/version, config highlights, access level achieved (none/anon/user/admin), evidence path, and next test ideas. This becomes both your attack plan and your report appendix.

HTTP(S): fingerprint, map, discover

Web services dominate many engagements. Fingerprint with whatweb, httpx tech flags, manual headers, and error pages. Identify frameworks, reverse proxies, and app servers. Virtual hosts matter — try names from recon, not only the IP.

Map the app: walk as an anonymous user, note auth entry points, APIs, uploads, admin paths, and parameters. Content discovery (ffuf, feroxbuster, gobuster) finds hidden paths; tune filters for status/size/word counts. Soft 404s will lie to you until you calibrate.

Default credentials and setup wizards still appear on appliances and forgotten admin panels. Try only against systems you are allowed to test, with logging, and stop after proof — do not pivot into destructive changes. Screenshots and requests are enough for many findings.

SMB and Windows-adjacent services

SMB (445/139) is a pillar of internal Windows testing. Check signing requirements, guest/null session behavior, accessible shares, and interesting files. Tools like smbmap, enum4linux, and Impacket utilities accelerate this — understand what each query does.

User enumeration and RID cycling can be noisy and policy-sensitive. Prefer low-and-slow, RoE-approved techniques. Finding a readable share with credentials or backups can outrank a flashy remote exploit for real impact.

Related services: RPC, WinRM, RDP (3389). For RDP, exposure itself may be the finding externally; do not brute force without explicit permission. NLA, banner, and reachability notes belong in the inventory even before creds exist.

SSH, databases, and directory services

SSH (22): record version, auth methods (password/publickey/keyboard-interactive), and whether root login appears allowed. Exploitation is rarely step one; key material exposure, weak creds (when authorized to test), and pivot use come later. Banner grabs with netcat/nmap still help inventory.

Databases (MySQL, Postgres, MSSQL, Mongo, Redis): unauthenticated exposure or default creds are critical findings. Do not bulk-dump customer data to “prove” access — a metadata query or non-sensitive proof is proportional. Exposure of a DB port to the WAN is often reportable even before auth success.

LDAP/Kerberos (389/636/88) signal directory services and AD. Enumerate carefully; authenticated AD enum is a whole discipline (BloodHound later). At this stage, identify role (DC vs member), note anonymous bind behavior if any, and flag for deeper AD methodology.

DNS, mail, and “odd ports”

DNS (53): check recursion on authorized targets, attempt zone transfers only against systems you may test (axfr), and review records for internal naming leaks. Open recursion is a risk class; AXFR success is high-impact misconfiguration when it reveals internal zones.

Mail (25/587/110/143/993/995): versions, auth advertisement, and open relay tests only when permitted. Be careful with send tests — do not spam real users. Often the finding is exposure plus weak auth, not writing a novel to the CEO.

Odd high ports often hide admin UIs, proxies, containers, or malware lab leftovers. Fingerprint with nmap -sV, browser, and netcat. Anything unknown goes into a “triage” queue rather than being ignored because it was not in the top 100 list.

Credential safety, lockouts, and signal vs noise

Account lockout policies turn careless spraying into a denial-of-service against the client’s users. Never spray without RoE, known policy, tight user lists, and slow rates. Prefer password auditing offline when hashes are obtained legitimately later in engagements.

Signal vs noise: a verbose FTP banner on an isolated lab printer may be low priority; an external Redis without auth is not. Use business context. Ask clients which hosts are crown jewels when prioritization is unclear.

When enum suggests a vulnerability, validate enough for a finding draft but avoid full exploit payload spam before you understand impact and stability — especially on production. Module progression will cover exploitation; here you build the map that makes exploitation deliberate.

Key concepts

Service enumeration
Protocol-specific collection of configuration, access level, and attack-relevant detail beyond port open/closed.
Null session
Unauthenticated or anonymous IPC/session behavior on Windows/SMB that may leak info if allowed.
Content discovery
Systematic discovery of hidden paths, vhosts, and parameters on web services.
Lockout risk
Account or resource disablement caused by too many failed auths — operational harm to the client.
Proportional proof
Minimum evidence that demonstrates risk without unnecessary data exposure or downtime.

Common mistakes

  • Password spraying every user list found on the internet against production AD
  • Dumping entire databases when SELECT version() proved the point
  • Ignoring virtual hosts and only testing http://IP/
  • Treating every NSE “VULNERABLE” label as confirmed without manual verification
  • Skipping share and file review on SMB because “no RCE yet”
  • Brute forcing SSH/RDP for hours instead of reporting exposure and moving on

Defender view

  • Hardening guides per service (SMB signing, disable null sessions, bind DBs to localhost/VPN) kill entire enum paths.
  • EDR and identity monitoring catch spraying and unusual LDAP/SMB enumeration patterns.
  • External attack surface management should find exposed admin and DB ports before testers do.

Operator checklist

  • Each high-value port has an enum note with evidence path
  • Unauthenticated checks completed before any spraying
  • Web targets have at least basic fingerprint + path discovery pass
  • SMB/HTTP findings include access level achieved (none/anon/user)
  • No lockout-prone activity without explicit RoE and rate plan

Example commands & patterns

# LAB / AUTHORIZED ONLY
whatweb -a 3 http://192.168.56.10/
ffuf -u http://192.168.56.10/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,204,301,302,403
smbmap -H 192.168.56.10
enum4linux -a 192.168.56.10
nc -nv 192.168.56.10 22
nmap -sV -p 22,80,445,3306 192.168.56.10 --script banner
dig axfr @192.168.56.10 lab.local

Practice drills

  1. On a lab Windows/Samba target, map shares and permissions; document anonymous vs authenticated access
  2. On a web target, find at least one non-obvious path with ffuf and explain your filter choices
  3. Banner-grab SSH and one database port; write proportional “exposure” finding text without dumping data
  4. Attempt a DNS zone transfer against a lab DNS you control; record success or failure with evidence
  5. Build a one-page personal checklist for ports 22, 80/443, 445, 3306/5432, 3389

Next: Carry your prioritized inventory into web hacking and exploitation modules — still evidence-first, still in scope.