Skip to main content

Active reconnaissance — Concepts

You are coming out of two weeks of silent intelligence. This week, we hit. Every packet you send can be seen, logged, correlated. A poorly tuned scan is an IDS that screams, a client who calls you, an engagement that starts in the red.

Reminder

A port scan against an IP you do not own and for which you have no written authorization is a hostile act in law in most jurisdictions, including when you find nothing. This entire lesson runs on your lab or on targets covered by a RoE.

What you will be able to do after this lesson​

  • Choose the right scan for the right moment (fast, complete, quiet, aggressive).
  • Read an Nmap result line by line, including filtered, open|filtered, unfiltered.
  • Enumerate a Windows service with enum4linux-ng, smbclient, crackmapexec.
  • Use Wireshark to verify what your scan actually puts on the wire.
  • Forge a packet by hand with Scapy when nmap does not do what you want.
  • Estimate the noise cost of a scan before you launch it.

1. The passive → active shift: what really changes​

In passive, nobody knows you exist. In active, your IP is in the target's logs. Three concrete consequences:

  1. Your traces are dated. An nmap -p- on victim.com, at 03:14 on 12 April, that one comes back.
  2. Your traces are attributable. Source IP, TCP/IP fingerprint, HTTP User-Agent, packet order — everything tells who you are.
  3. Defenses fight back. An IDS can block your IP on the fly. A WAF can cut you off. A SOC can call your client to check.

Well run, active reconnaissance stays undetectable or negligible. Poorly run, it is the "incident" paragraph in the CISO's report.


2. The logic of scanning in layers​

A pentester never launches nmap -A --script vuln first. We move in layers, from the thinnest to the widest. Each layer answers one question.

LayerQuestionToolNoise
1. Host discoveryWho is alive?nmap -sn, arp-scanLow
2. Port sweepWhat is listening?nmap -sS -p-Medium
3. Version detectionWho is listening, in which version?nmap -sVMedium-high
4. Targeted NSE scriptsWhat does this service say?nmap --script <specific>Variable
5. Application enumerationAccounts, shares, endpointsenum4linux-ng, gobusterHigh

The rule: each layer builds on the previous one. You run -sV only on open ports, not on all 65,535 blindly. You launch NSE scripts only on identified services, not by default.


3. Nmap port states — stop misreading them​

Six possible states. Do not mix them up again:

StateWhat it means
openA service is listening and replies.
closedNothing is listening — the target replies with RST (TCP) or ICMP port unreachable (UDP).
filteredA firewall absorbs your packet. Neither yes nor no.
unfilteredThe target replies but we do not know whether the port is open (rare, on -sA).
open|filteredNo reply — either open or filtered (UDP does this often).
closed|filteredSame idea, but we lean closed (zombie scan).

What this changes for you:

  • A filtered port is information: someone put a firewall there, so something sensitive sits behind it.
  • An open|filtered port on UDP is very common: rerun -sU with --reason to decide.
  • An nmap range that returns filtered everywhere is often a network firewall, not a powered-off host.

4. TCP scan techniques — which one, for what​

Techniquenmap optionWhat it doesWhen to choose it
SYN scan (half-open)-sSSends a SYN, reads SYN/ACK, does not finish the handshake.Standard. Fast and quiet. Requires root.
Connect scan-sTFull handshake (uses the OS).Without root, or to avoid certain fingerprints.
ACK scan-sAMaps firewalls (not open ports).Detect a stateful firewall vs a stateless one.
FIN / NULL / Xmas-sF / -sN / -sXSends abnormal flag combinations.Evade poorly configured firewalls (RFC 793).
Idle scan-sI zombieUses a third machine as a relay. Your IP never talks to the target.Extreme stealth (and complexity).
UDP scan-sUForces a UDP scan. Very slow.Discover DNS, SNMP, NTP, IKE, SIP…

For 90% of engagements: -sS on TCP, -sU -p <interesting UDP ports> on UDP when it is useful.


5. Timing templates — understanding -T​

nmap offers six speeds: -T0 to -T5. They are not gifts; they are choices.

TemplateThroughputUse
-T0 paranoid5 min between packetsReserved for extreme evasion against IDS.
-T1 sneaky15 s between packetsStill for evasion, but less slow.
-T2 polite400 ms between packetsFragile hardware, industrial networks.
-T3 normalDefault.Classic pentest in the lab or on a LAN.
-T4 aggressiveFast.Robust target, wide connection.
-T5 insaneVery fast.Lower accuracy, frequent false negatives.

Rule: -T3 unless you have a precise reason to do otherwise. -T4 on modern cloud targets. Never -T5 in prod, even a noisy one.

You can tune finely with --max-rate, --min-rate, --scan-delay, --host-timeout — but 95% of the time a -T is enough.


6. NSE scripts — enormous power, enormous caution​

nmap ships more than 600 scripts (/usr/share/nmap/scripts/). They are grouped by category. The most useful:

CategoryWhat it doesCaution
default (or -sC)Common, non-destructive scripts.Low.
safeDoes not degrade the service.Low.
discoveryFinds things, without exploiting.Low.
versionImproves version detection.Low.
authDetects auth configurations, sometimes tries logins.Medium.
vulnDetects known vulnerabilities. Often, it partially triggers them.High.
exploitActively exploits.Do not launch without a clear intent.
intrusiveCan take the service down.Never launch on prod.
dosTakes the service down.Forbidden outside the lab.

Good practice: --script "safe and default" on a discovery scan. Targeted scripts (smb-vuln-*, http-shellshock, and so on) once you have a lead.

Bad practice: --script vuln on a wide sweep. You break things and you will not know which one.


7. Windows / SMB enumeration​

On a Windows / Active Directory estate, the real gold mine is SMB (port 445) and LDAP (389, 636). The tools:

ToolWhat it does
enum4linux-ngEnumerates users, groups, shares, policy via a null session or with creds.
smbclient -L //cible/ -NLists shares without authentication.
crackmapexec smb <cible>The SMB Swiss army knife: banner, shares, auth tests, remote execution.
nxc smb <cible>Maintained successor of crackmapexec (NetExec).
smbmap -H <cible> -u <user> -p <pass>Lists rights on each share.
ldapsearch -x -H ldap://<cible>Anonymous LDAP queries if allowed.

What we look for:

  • A null session (-u '' -p '') that yields the user list = gold.
  • A readable SYSVOL or NETLOGON share with no password = abnormal, except on a DC.
  • IPC$, ADMIN$, C$ shares reachable with a standard domain account.
  • The password policy (length, expiry, lockout) — useful for password spraying later.

8. Wireshark — verify what you actually emit​

Wireshark is not an offensive tool, strictly speaking. But a pentester who never uses it is a blind pentester.

Three uses:

  1. Verify your own traffic. Launch an nmap and watch Wireshark: see how many packets you really send. An nmap -T4 on a /24 can send tens of thousands of SYN in 30 seconds.
  2. Understand errors. A scan that returns filtered — why? Is return ICMP blocked, or is the RST absorbed?
  3. Find surprise protocols. A classic nmap sees ports. Wireshark sees conversations — a chatty mDNS, an LLMNR left enabled, an Elasticsearch that answers in broadcast.

Filters to know by heart:

tcp.flags.syn == 1 and tcp.flags.ack == 0       # outbound SYN
tcp.flags.reset == 1 # RST received
smb2 # SMB2 traffic
dns.qry.name contains "internal" # suspicious DNS queries

9. Scapy — when nmap is no longer enough​

Scapy is a Python library that lets you build a packet by hand, field by field. Useful when:

  • You want to test a specific flag combination that nmap does not offer natively.
  • You want to emit a single packet and see the reply in the clear.
  • You want to build light protocol fuzzing.

The vital minimum:

from scapy.all import IP, TCP, UDP, ICMP, sr1

response = sr1(IP(dst="10.10.10.12") / TCP(dport=445, flags="S"), timeout=2, verbose=0)
if response and response.haslayer(TCP):
print("Flags received:", response[TCP].flags)

flags coming back:

  • 0x12 (SYN+ACK) → the port is open.
  • 0x14 (RST+ACK) → the port is closed.
  • None → filtered.

You just wrote, in three lines, a port scan that bypasses the nmap signatures some IDS recognize. That is the power of Scapy.


10. The mistakes that cost​

  • Launching -A first. You mix discovery, versions, OS, scripts and traceroute. You no longer know what comes from where. Work in layers.
  • Trusting the first scan. A port can be filtered because of a transient IPS. Rerun, correlate.
  • Forgetting UDP. You miss SNMP, IKE, SIP, TFTP — services that often hold the key.
  • Not capturing. Always record results with -oA <prefix>. The .xml file feeds msfconsole → db_import.
  • Scanning at night on a corporate LAN. The SOC does not sleep. Warn the escalation contact first.
  • Using a single IP address. An IP burned at the start of the engagement = a slowed engagement. Plan a fallback (VPN, second interface).

11. What to remember​

  • Active = packets at the target. Register that mentally on every command.
  • Scan in layers: discovery → ports → versions → targeted NSE.
  • Six port states. Each one tells a story.
  • -T3 by default, -sS by default. We tune after that.
  • NSE: safe by default, vuln only on identified targets, intrusive never without a plan.
  • SMB is the Windows gold mine — learn nxc smb by heart.
  • Wireshark to understand, Scapy to build.

Next lesson: we take the week 1 lab back, we add a second Linux victim, and we map everything, cleanly.