ZeroBox

Network Discovery & Port Scanning Guide

Master network port scanning and host enumeration using Nmap, Rustscan, SNMP, and SMB discovery techniques.

nmaprustscanmasscansnmpwalksmbmap

Network reconnaissance is the foundational phase of any assessment. Fast port discovery combined with targeted script scans provides the attack surface blueprint.

1. TCP Port Scanning Workflows

Initial Fast Scan

Scan the top 1000 TCP ports with version detection and default safe scripts:

nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}

Full Exhaustive Scan

Scan all 65,535 TCP ports to discover non-standard services:

nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}

Turbo RustScan

Asynchronous port scanner that pipes directly into Nmap:

rustscan -a {TARGET_IP} -r 1-65535 --ulimit 5000 -- -sC -sV -oN rustscan.txt

2. UDP Service Discovery

Identify critical UDP services like SNMP, TFTP, DNS, and NTP:

sudo nmap -sU --top-ports 20 -Pn --open -oN nmap_udp.txt {TARGET_IP}

3. Supplementary Enumeration

Always verify exposed web ports and transition to 02. Web Content Discovery & Directory Fuzzing or pivot via 09. Pivoting, Tunnels & Lateral Movement.

More CPTS notes

Keep these notes in your own private vault. Open CPTS notes in ZeroBox