ZeroBox

Phase 02: Protocol & Service Enumeration

Deeply inspect every discovered service without active exploitation, identifying versions, endpoints, and misconfigurations. This phase has 18 checklist items. Placeholders such as {TARGET_IP} are values for your target.

Universal Service Version Matrix

Banner Grabbing & Service Response Check

Read raw banners on all open ports to identify unmasked daemons.

nc -nv {TARGET_IP} {PORT} or curl -I http://{TARGET_IP}:{PORT}

Nmap Safe NSE Service-Specific Scripts

Gather verbose capabilities without triggering active exploits.

nmap -sC --script "safe and discovery" -p {PORT} {TARGET_IP}

Branch A: HTTP / HTTPS Web Surface Inspection

Technology Stack Fingerprinting (WhatWeb, Wappalyzer)

Detect web server, CMS, programming framework (PHP, Node, Django), and proxy headers.

whatweb -a 3 http://{TARGET_IP}/

Source Code, Comments & Metadata Inspection

Check HTML comments, developer notes, /robots.txt, /sitemap.xml, and exposed .git/.env.

curl -s http://{TARGET_IP}/ | grep -E "<!--|TODO|DEBUG|api"

Virtual Host & Subdomain Enumeration

Discover hidden virtual hosts routed on the same IP.

ffuf -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u http://{TARGET_IP}/ -H "Host: FUZZ.{TARGET_DOMAIN}" -mc 200,301,302 -fs {BASELINE_SIZE}

Recursive Directory & Endpoint Fuzzing

Identify hidden administrative panels, upload directories, API routes, and backups.

ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.txt,.bak,.json,.sh -ac

API & Modern Framework Assessment (REST/GraphQL)

Test for GraphQL introspection or OpenAPI / Swagger endpoints at /api, /swagger, /docs.

curl -s -X POST http://{TARGET_IP}/graphql -H "Content-Type: application/json" -d '{"query": "{__schema{types{name}}}"}'

Branch B: File Sharing & Infrastructure (SMB, FTP, NFS, RPC)

FTP Anonymous Login & File Retrieval

Check if anonymous FTP login is allowed and download all readable files.

ftp -n {TARGET_IP} <<<'user anonymous ""'

SMB NULL / Guest Session & Share Permissions

Verify read/write permissions on public, IPC$, and hidden shares.

netexec smb {TARGET_IP} -u "" -p "" --shares or smbclient -N -L //{TARGET_IP}/

NFS Public Export Mounts Inspection

Check for NFS exports mountable without authentication or with no_root_squash.

showmount -e {TARGET_IP}

RPC User & Group Domain Enumeration

Query users, groups, and domain info through unauthenticated MSRPC.

rpcclient -U "" -N {TARGET_IP} -c "enumdomusers; enumdomgroups"

Branch C: Remote Access & Administration (SSH, RDP, WinRM)

SSH Banner & Algorithm Audit

Check exact OpenSSH version for known vulnerabilities or weak auth methods.

nc -nv {TARGET_IP} 22 or ssh -v {TARGET_IP}

RDP / WinRM Service Handshake Inspection

Verify WinRM authentication status and RDP NLA encryption settings.

nxc winrm {TARGET_IP} or nxc rdp {TARGET_IP}

Branch D: Database Engine Enumeration

Database Default Credentials Check (sa, root, postgres)

Test blank or default administrative passwords on exposed database ports.

nxc mssql {TARGET_IP} -u sa -p "" or mysql -h {TARGET_IP} -u root

Redis / MongoDB Unauthenticated Access

Verify unauthenticated database commands, key inspection, or rogue module injection.

redis-cli -h {TARGET_IP} info or mongosh --host {TARGET_IP}

Branch E: Network Management & Discovery (DNS, SNMP, LDAP)

DNS Zone Transfer (AXFR) Test

Attempt full zone transfer to extract all internal domain hostnames.

dig axfr @{TARGET_IP} {DOMAIN}

SNMP Community String Fuzzing & Walk

Expose system processes, network interfaces, and potential credentials in SNMP OIDs.

onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt {TARGET_IP}; snmpwalk -c public -v2c {TARGET_IP}

LDAP Anonymous Bind & Active Directory Recon

Extract Active Directory domain naming contexts without credentials.

ldapsearch -x -H ldap://{TARGET_IP} -s base namingcontexts

All phases

  1. Host Discovery & Surface Mapping
  2. Protocol & Service Enumeration
  3. Vulnerability Identification & Threat Modeling
  4. Foothold Execution & Initial Access
  5. Shell Stabilization & Context Triage
  6. Internal System & Network Reconnaissance
  7. Privilege Escalation & Lateral Movement
  8. Post-Exploitation, Flag Vault & Artifact Collection

Tick items off per machine. ZeroBox tracks checklist progress for every target. Open the methodology checklist