Network Discovery & Port Scanning Guide
Master network port scanning and host enumeration using Nmap, Rustscan, SNMP, and SMB discovery techniques.
nmaprustscanmasscansnmpwalksmbmap
Network reconnaissance is the foundational phase of any assessment. Fast port discovery combined with targeted script scans provides the attack surface blueprint.
1. TCP Port Scanning Workflows
Initial Fast Scan
Scan the top 1000 TCP ports with version detection and default safe scripts:
nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}
Full Exhaustive Scan
Scan all 65,535 TCP ports to discover non-standard services:
nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}
Turbo RustScan
Asynchronous port scanner that pipes directly into Nmap:
rustscan -a {TARGET_IP} -r 1-65535 --ulimit 5000 -- -sC -sV -oN rustscan.txt
2. UDP Service Discovery
Identify critical UDP services like SNMP, TFTP, DNS, and NTP:
sudo nmap -sU --top-ports 20 -Pn --open -oN nmap_udp.txt {TARGET_IP}
3. Supplementary Enumeration
- SNMP Community String:
snmpwalk -v 2c -c public {TARGET_IP} - SMB Guest Shares:
smbmap -H {TARGET_IP} -u "" -p ""
Always verify exposed web ports and transition to 02. Web Content Discovery & Directory Fuzzing or pivot via 09. Pivoting, Tunnels & Lateral Movement.
More CPTS notes
- 02. Web Content Discovery & Directory Fuzzing
- 03. Web Application Exploitation & Injection
- 04. Linux Privilege Escalation Master Guide
- 05. Windows Local Privilege Escalation & LOLBAS
- 06. Active Directory Attack Paths & Domain Enumeration
- 07. Kerberos Exploitation: AS-REP & Kerberoasting
- 08. Active Directory Certificate Services (AD CS) Abuse
- 09. Pivoting, Tunnels & Lateral Movement
- 10. Password Cracking & Hash Identification
- 11. Offensive File Transfers Across Restricted Networks
- 12. Interactive TTY Stabilization & Terminal Spawning
Keep these notes in your own private vault. Open CPTS notes in ZeroBox