Skip to content
Paul Marinos
Menu

Recon & Enumeration

Building the attack surface before touching anything hard — host discovery, port and service scanning, subdomain and asset mapping, and web content discovery, with the OPSEC that decides scan order.

Recon decides the shape of everything after it. The finding is more often here — a forgotten host, an admin panel, a subdomain nobody remembered owning — than in some clever exploit later. The discipline is to map broadly and quietly first, then go deep only where the map says it is worth the noise.

nmap -sn 10.0.0.0/24: ping sweep, no port scan. Output: which hosts are up. Next: the inventory you scan properly. On networks that block ICMP, -sn undercounts — fall back to -Pn and let the port scan decide liveness.

nmap -sV -sC -p- <target>: full TCP sweep, version detection, default scripts. Output: open ports, service versions, script findings. Next: the version strings drive the vulnerability hypothesis, and an unexpected open port is often the finding itself. -p- is slow; scan --top-ports 1000 first for a fast picture, then run all ports in the background.

masscan -p1-65535 <target> --rate 10000: asynchronous scanner built for speed at scale. Output: open ports, fast, across large ranges. Next: masscan to find open ports across a wide range, then nmap -sV -sC against just those ports for detail. The rate is a loudness dial — high rate is fast and conspicuous.

Two flags worth knowing deliberately: -Pn skips host discovery and treats every host as up, which is right behind a firewall that drops pings but wrong on a /16 where it wastes the scan on dead space. -sU scans UDP, which is slow and routinely skipped — and so is where DNS, SNMP and IKE findings hide precisely because everyone skips it.

amass enum -passive -d target.com: asset discovery from public sources. Output: subdomains, from certificate transparency, passive DNS and other feeds. Next: the external footprint, built without sending the target a single packet.

subfinder -d target.com -all: fast passive subdomain enumeration. Output: subdomains from a broad set of sources. Next: faster and lighter than amass for a first pass; run both and take the union, because they draw on overlapping-but-different sources.

dnsx -l subs.txt -a -resp: resolve a candidate list and keep the live ones. Output: which names resolve, and to what. Next: separates real assets from certificate-transparency noise, and the IPs cluster hosts into the netblocks worth scanning.

Passive first is the rule and it is an OPSEC decision, not only an efficiency one: certificate transparency and passive DNS touch no target infrastructure, so they cost the target nothing to see. Active resolution and scanning do. This is also exactly the internal telemetry a defender mines from the other side — your enumeration is their early signal.

httpx -l hosts.txt -sc -title -tech-detect: probe a host list for live web services. Output: status code, page title, detected technology per host. Next: the technology fingerprint shapes which attacks are plausible, and titles reveal admin panels and forgotten apps faster than anything else in recon.

ffuf -w wordlist -u https://target/FUZZ -mc 200,301,403: content and directory discovery. Output: paths that exist, by status code. Next: a 403 is as interesting as a 200 — present-but-forbidden is a boundary worth pushing. Filter the wildcard noise with -fs <size> (filter by response size) or -fw once you see what the catch-all page returns; without it a wildcard host marks everything as found.

feroxbuster -u https://target -x php,html,txt: recursive content discovery. Output: discovered paths, recursing into directories it finds. Next: recursion is the difference from a flat ffuf run — it follows /admin into /admin/backup on its own. The extension list should match the stack httpx fingerprinted.

The output is not the finding; the reading is. Three habits carry most of the value:

  • A version string is a hypothesis, not a vulnerability. It tells you what to check, and banners lie — patched backports keep old version numbers, and hardened services fake them.
  • The unexpected is the finding. A port, a subdomain, a title that should not exist is worth more than a clean scan of what you expected.
  • Feed it forward deliberately. Recon output is the input to web testing and cloud enumeration; a fingerprint you noted and did not act on is wasted collection.

Recon feeds the web application methodology directly — the surface it maps is the surface that gets tested. The passive-source discipline is the offensive face of collection and sourcing, and every active probe here is an event in someone’s data pipeline, which is what makes scan loudness a real decision rather than a preference.

Graph View

Last updated:

Spotted an error on this page? Report it.