Active Scanning & Enumeration: Mapping the Attack Surface

The VMs are running and the network is segmented. Now comes the question every engagement turns on: what’s actually out there? This Cover6 Community session picks up where the Home Lab series left off and maps the attack surface — the quiet, methodical part of hacking that most of the real work lives in.

Use this post as your read-ahead, then come back to it for the commands.

YouTube thumbnailYouTube icon

Active vs passive, and why it’s loud

Passive recon watches from a distance without touching the target. Active scanning actually sends packets at it — and the moment you do, you’re visible. That’s the trade: active scanning gives you real answers about what’s running, and it leaves a trace in the target’s logs. (Which is exactly why running it yourself makes you a better defender: you learn what your own noise looks like from the other chair.)

Everything below runs against a lab you own or are authorized to test. Never someone else’s network.

Nmap fundamentals

Nmap is the backbone of enumeration. Three capabilities carry most of the work:

  • Host discovery — which machines on the network are actually up.
  • Version detection — what software and version each open port is running.
  • OS fingerprinting — a best guess at the operating system.

A practical starting scan — top ports, service versions, only what’s open:

nmap -v -T4 -sV -Pn --top-ports 100 --open target

Widen to all ports when the first pass is thin:

nmap -v -T4 -sV -Pn -p- --open target

Add OS fingerprinting when you want the fuller picture (needs elevated privileges):

nmap -O -sV target

The Nmap Scripting Engine

NSE turns Nmap from a port scanner into an enumeration toolkit. The default script set is the one you reach for first — safe, informative, and run with -sC:

nmap -sC -sV target

From there, NSE has scripts for specific services (SMB, HTTP, SSL, and more). The skill is knowing a script exists for the service you’re looking at, not memorizing all of them.

Service enumeration

Once a port is open, enumerate the service behind it:

  • SMB — enum4linux pulls shares, users, and policies from Windows/Samba hosts; CrackMapExec sweeps SMB across a range and is a workhorse for internal enumeration.
  • Banner grabbing — netcat and curl ask a service to identify itself. A quick nc target 80 or curl -I http://target often hands you the software and version straight away.

Each answer narrows the next question, and the whole thing is just: identify hosts → identify open ports → identify the services → identify the vulnerabilities.

Document the attack surface first

The output of this phase isn’t a shell — it’s a map. Before you exploit anything, write down every host, every open port, every service and version. On a real engagement you might have hundreds of hosts after the first week; the map is how you stay on top of them, and it’s half of what the client is paying for.

That’s the lesson from the Odapeeka State University scenario we walked: the attacker spent hours doing exactly this enumeration before the ransomware ever detonated. Security Onion caught some of it and missed some of it — and knowing which is which is the whole game for a defender. The noisy recon was there to be seen. Someone had to be looking.

Practice on a lab you own, free

The way to get fast at enumeration is to do it against a target built for it. First Shell is the free Cover6 lab that runs in your browser — you get a target you’re authorized to scan and attack, so you can map it, find the weak service, and prove it.

👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/

As you work, run the methodology from this post: discover hosts, scan for open ports and versions, enumerate each service, write it all down.

Where this path leads

Active scanning and enumeration are foundational Penetration Tester work on Chrysalus. Build your free profile and add your attack-surface map as a project.

Watch the replay

We ran this live in the Cover6 Community — Nmap, NSE, and service enumeration on the lab we built together, plus a breakdown of the real recon behind the Odapeeka scenario. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.

The 6 — Free Newsletter

Job openings, new courses, free workshops, and what’s working in cyber careers right now — straight to your inbox.

Free forever. Confirm by email, unsubscribe any time. We never share your address.

Shopping Cart
Scroll to Top