The VMs are running and the network is segmented. Now comes the question every engagement turns on: what’s actually out there? This Cover6 Community session picks up where the Home Lab series left off and maps the attack surface — the quiet, methodical part of hacking that most of the real work lives in.
Use this post as your read-ahead, then come back to it for the commands.
Active vs passive, and why it’s loud
Passive recon watches from a distance without touching the target. Active scanning actually sends packets at it — and the moment you do, you’re visible. That’s the trade: active scanning gives you real answers about what’s running, and it leaves a trace in the target’s logs. (Which is exactly why running it yourself makes you a better defender: you learn what your own noise looks like from the other chair.)
Everything below runs against a lab you own or are authorized to test. Never someone else’s network.
Nmap fundamentals
Nmap is the backbone of enumeration. Three capabilities carry most of the work:
- Host discovery — which machines on the network are actually up.
- Version detection — what software and version each open port is running.
- OS fingerprinting — a best guess at the operating system.
A practical starting scan — top ports, service versions, only what’s open:
nmap -v -T4 -sV -Pn --top-ports 100 --open target
Widen to all ports when the first pass is thin:
nmap -v -T4 -sV -Pn -p- --open target
Add OS fingerprinting when you want the fuller picture (needs elevated privileges):
nmap -O -sV target
The Nmap Scripting Engine
NSE turns Nmap from a port scanner into an enumeration toolkit. The default script set is the one you reach for first — safe, informative, and run with -sC:
nmap -sC -sV target
From there, NSE has scripts for specific services (SMB, HTTP, SSL, and more). The skill is knowing a script exists for the service you’re looking at, not memorizing all of them.
Service enumeration
Once a port is open, enumerate the service behind it:
- SMB —
enum4linuxpulls shares, users, and policies from Windows/Samba hosts; CrackMapExec sweeps SMB across a range and is a workhorse for internal enumeration. - Banner grabbing —
netcatandcurlask a service to identify itself. A quicknc target 80orcurl -I http://targetoften hands you the software and version straight away.
Each answer narrows the next question, and the whole thing is just: identify hosts → identify open ports → identify the services → identify the vulnerabilities.
Document the attack surface first
The output of this phase isn’t a shell — it’s a map. Before you exploit anything, write down every host, every open port, every service and version. On a real engagement you might have hundreds of hosts after the first week; the map is how you stay on top of them, and it’s half of what the client is paying for.
That’s the lesson from the Odapeeka State University scenario we walked: the attacker spent hours doing exactly this enumeration before the ransomware ever detonated. Security Onion caught some of it and missed some of it — and knowing which is which is the whole game for a defender. The noisy recon was there to be seen. Someone had to be looking.
Practice on a lab you own, free
The way to get fast at enumeration is to do it against a target built for it. First Shell is the free Cover6 lab that runs in your browser — you get a target you’re authorized to scan and attack, so you can map it, find the weak service, and prove it.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
As you work, run the methodology from this post: discover hosts, scan for open ports and versions, enumerate each service, write it all down.
Where this path leads
Active scanning and enumeration are foundational Penetration Tester work on Chrysalus. Build your free profile and add your attack-surface map as a project.
- Read the Pentester Roadmap 2026.
- Want the deeper version? The Pentester Prep Labs take this from fundamentals to exam-ready.
- Use the Cover6 Field Manual as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community — Nmap, NSE, and service enumeration on the lab we built together, plus a breakdown of the real recon behind the Odapeeka scenario. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
