Phase 02: Protocol & Service Enumeration
Deeply inspect every discovered service without active exploitation, identifying versions, endpoints, and misconfigurations. This phase has 18 checklist items. Placeholders such as {TARGET_IP} are values for your target.
Universal Service Version Matrix
Banner Grabbing & Service Response Check
Read raw banners on all open ports to identify unmasked daemons.
nc -nv {TARGET_IP} {PORT} or curl -I http://{TARGET_IP}:{PORT}Nmap Safe NSE Service-Specific Scripts
Gather verbose capabilities without triggering active exploits.
nmap -sC --script "safe and discovery" -p {PORT} {TARGET_IP}
Branch A: HTTP / HTTPS Web Surface Inspection
Technology Stack Fingerprinting (WhatWeb, Wappalyzer)
Detect web server, CMS, programming framework (PHP, Node, Django), and proxy headers.
whatweb -a 3 http://{TARGET_IP}/Source Code, Comments & Metadata Inspection
Check HTML comments, developer notes, /robots.txt, /sitemap.xml, and exposed .git/.env.
curl -s http://{TARGET_IP}/ | grep -E "<!--|TODO|DEBUG|api"Virtual Host & Subdomain Enumeration
Discover hidden virtual hosts routed on the same IP.
ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP}/ -H "Host: FUZZ.{TARGET_DOMAIN}" -mc 200,301,302 -fs {BASELINE_SIZE}Recursive Directory & Endpoint Fuzzing
Identify hidden administrative panels, upload directories, API routes, and backups.
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.txt,.bak,.json,.sh -acAPI & Modern Framework Assessment (REST/GraphQL)
Test for GraphQL introspection or OpenAPI / Swagger endpoints at /api, /swagger, /docs.
curl -s -X POST http://{TARGET_IP}/graphql -H "Content-Type: application/json" -d '{"query": "{__schema{types{name}}}"}'
Branch B: File Sharing & Infrastructure (SMB, FTP, NFS, RPC)
FTP Anonymous Login & File Retrieval
Check if anonymous FTP login is allowed and download all readable files.
ftp -n {TARGET_IP} <<<'user anonymous ""'SMB NULL / Guest Session & Share Permissions
Verify read/write permissions on public, IPC$, and hidden shares.
netexec smb {TARGET_IP} -u "" -p "" --shares or smbclient -N -L //{TARGET_IP}/NFS Public Export Mounts Inspection
Check for NFS exports mountable without authentication or with no_root_squash.
showmount -e {TARGET_IP}RPC User & Group Domain Enumeration
Query users, groups, and domain info through unauthenticated MSRPC.
rpcclient -U "" -N {TARGET_IP} -c "enumdomusers; enumdomgroups"
Branch C: Remote Access & Administration (SSH, RDP, WinRM)
SSH Banner & Algorithm Audit
Check exact OpenSSH version for known vulnerabilities or weak auth methods.
nc -nv {TARGET_IP} 22 or ssh -v {TARGET_IP}RDP / WinRM Service Handshake Inspection
Verify WinRM authentication status and RDP NLA encryption settings.
nxc winrm {TARGET_IP} or nxc rdp {TARGET_IP}
Branch D: Database Engine Enumeration
Database Default Credentials Check (sa, root, postgres)
Test blank or default administrative passwords on exposed database ports.
nxc mssql {TARGET_IP} -u sa -p "" or mysql -h {TARGET_IP} -u rootRedis / MongoDB Unauthenticated Access
Verify unauthenticated database commands, key inspection, or rogue module injection.
redis-cli -h {TARGET_IP} info or mongosh --host {TARGET_IP}
Branch E: Network Management & Discovery (DNS, SNMP, LDAP)
DNS Zone Transfer (AXFR) Test
Attempt full zone transfer to extract all internal domain hostnames.
dig axfr @{TARGET_IP} {DOMAIN}SNMP Community String Fuzzing & Walk
Expose system processes, network interfaces, and potential credentials in SNMP OIDs.
onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt {TARGET_IP}; snmpwalk -c public -v2c {TARGET_IP}LDAP Anonymous Bind & Active Directory Recon
Extract Active Directory domain naming contexts without credentials.
ldapsearch -x -H ldap://{TARGET_IP} -s base namingcontexts
All phases
- Host Discovery & Surface Mapping
- Protocol & Service Enumeration
- Vulnerability Identification & Threat Modeling
- Foothold Execution & Initial Access
- Shell Stabilization & Context Triage
- Internal System & Network Reconnaissance
- Privilege Escalation & Lateral Movement
- Post-Exploitation, Flag Vault & Artifact Collection
Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist