Phase 01: Host Discovery & Surface Mapping
Scan the target host across TCP and UDP ports, detect open services, and fingerprint the underlying operating system. This phase has 4 checklist items. Placeholders such as {TARGET_IP} are values for your target.
Port Scanning & Host Discovery
Fast SYN Scan (Top 1000 TCP Ports)
Quick sweep of common TCP ports with default scripts and service versions.
nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}Full 65,535 TCP Exhaustive Port Sweep
Ensure no non-standard or high-numbered services (e.g. 8080, 8443, 9001) are missed.
nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}Top UDP Service Discovery Scan
Probe high-value UDP targets including SNMP, DNS, TFTP, and NTP.
sudo nmap -sU --top-ports 100 -Pn --open -oN nmap_udp.txt {TARGET_IP}OS Fingerprinting & TCP/IP Stack Analysis
Determine exact kernel/OS flavor (Linux distro, Windows build, BSD).
nmap -O --osscan-guess {TARGET_IP}
All phases
- Host Discovery & Surface Mapping
- Protocol & Service Enumeration
- Vulnerability Identification & Threat Modeling
- Foothold Execution & Initial Access
- Shell Stabilization & Context Triage
- Internal System & Network Reconnaissance
- Privilege Escalation & Lateral Movement
- Post-Exploitation, Flag Vault & Artifact Collection
Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist