Active reconnaissance — Concepts
You are coming out of two weeks of silent intelligence. This week, we hit. Every packet you send can be seen, logged, correlated. A poorly tuned scan is an IDS that screams, a client who calls you, an engagement that starts in the red.
A port scan against an IP you do not own and for which you have no written authorization is a hostile act in law in most jurisdictions, including when you find nothing. This entire lesson runs on your lab or on targets covered by a RoE.
What you will be able to do after this lesson
- Choose the right scan for the right moment (fast, complete, quiet, aggressive).
- Read an Nmap result line by line, including
filtered,open|filtered,unfiltered. - Enumerate a Windows service with
enum4linux-ng,smbclient,crackmapexec. - Use Wireshark to verify what your scan actually puts on the wire.
- Forge a packet by hand with Scapy when
nmapdoes not do what you want. - Estimate the noise cost of a scan before you launch it.
1. The passive → active shift: what really changes
In passive, nobody knows you exist. In active, your IP is in the target's logs. Three concrete consequences:
- Your traces are dated. An
nmap -p-onvictim.com, at 03:14 on 12 April, that one comes back. - Your traces are attributable. Source IP, TCP/IP fingerprint, HTTP
User-Agent, packet order — everything tells who you are. - Defenses fight back. An IDS can block your IP on the fly. A WAF can cut you off. A SOC can call your client to check.
Well run, active reconnaissance stays undetectable or negligible. Poorly run, it is the "incident" paragraph in the CISO's report.
2. The logic of scanning in layers
A pentester never launches nmap -A --script vuln first. We move in layers, from the thinnest to the widest. Each layer answers one question.
| Layer | Question | Tool | Noise |
|---|---|---|---|
| 1. Host discovery | Who is alive? | nmap -sn, arp-scan | Low |
| 2. Port sweep | What is listening? | nmap -sS -p- | Medium |
| 3. Version detection | Who is listening, in which version? | nmap -sV | Medium-high |
| 4. Targeted NSE scripts | What does this service say? | nmap --script <specific> | Variable |
| 5. Application enumeration | Accounts, shares, endpoints | enum4linux-ng, gobuster | High |
The rule: each layer builds on the previous one. You run -sV only on open ports, not on all 65,535 blindly. You launch NSE scripts only on identified services, not by default.
3. Nmap port states — stop misreading them
Six possible states. Do not mix them up again:
| State | What it means |
|---|---|
open | A service is listening and replies. |
closed | Nothing is listening — the target replies with RST (TCP) or ICMP port unreachable (UDP). |
filtered | A firewall absorbs your packet. Neither yes nor no. |
unfiltered | The target replies but we do not know whether the port is open (rare, on -sA). |
open|filtered | No reply — either open or filtered (UDP does this often). |
closed|filtered | Same idea, but we lean closed (zombie scan). |
What this changes for you:
- A
filteredport is information: someone put a firewall there, so something sensitive sits behind it. - An
open|filteredport on UDP is very common: rerun-sUwith--reasonto decide. - An
nmaprange that returnsfilteredeverywhere is often a network firewall, not a powered-off host.
4. TCP scan techniques — which one, for what
| Technique | nmap option | What it does | When to choose it |
|---|---|---|---|
| SYN scan (half-open) | -sS | Sends a SYN, reads SYN/ACK, does not finish the handshake. | Standard. Fast and quiet. Requires root. |
| Connect scan | -sT | Full handshake (uses the OS). | Without root, or to avoid certain fingerprints. |
| ACK scan | -sA | Maps firewalls (not open ports). | Detect a stateful firewall vs a stateless one. |
| FIN / NULL / Xmas | -sF / -sN / -sX | Sends abnormal flag combinations. | Evade poorly configured firewalls (RFC 793). |
| Idle scan | -sI zombie | Uses a third machine as a relay. Your IP never talks to the target. | Extreme stealth (and complexity). |
| UDP scan | -sU | Forces a UDP scan. Very slow. | Discover DNS, SNMP, NTP, IKE, SIP… |
For 90% of engagements: -sS on TCP, -sU -p <interesting UDP ports> on UDP when it is useful.
5. Timing templates — understanding -T
nmap offers six speeds: -T0 to -T5. They are not gifts; they are choices.
| Template | Throughput | Use |
|---|---|---|
-T0 paranoid | 5 min between packets | Reserved for extreme evasion against IDS. |
-T1 sneaky | 15 s between packets | Still for evasion, but less slow. |
-T2 polite | 400 ms between packets | Fragile hardware, industrial networks. |
-T3 normal | Default. | Classic pentest in the lab or on a LAN. |
-T4 aggressive | Fast. | Robust target, wide connection. |
-T5 insane | Very fast. | Lower accuracy, frequent false negatives. |
Rule: -T3 unless you have a precise reason to do otherwise. -T4 on modern cloud targets. Never -T5 in prod, even a noisy one.
You can tune finely with --max-rate, --min-rate, --scan-delay, --host-timeout — but 95% of the time a -T is enough.
6. NSE scripts — enormous power, enormous caution
nmap ships more than 600 scripts (/usr/share/nmap/scripts/). They are grouped by category. The most useful:
| Category | What it does | Caution |
|---|---|---|
default (or -sC) | Common, non-destructive scripts. | Low. |
safe | Does not degrade the service. | Low. |
discovery | Finds things, without exploiting. | Low. |
version | Improves version detection. | Low. |
auth | Detects auth configurations, sometimes tries logins. | Medium. |
vuln | Detects known vulnerabilities. Often, it partially triggers them. | High. |
exploit | Actively exploits. | Do not launch without a clear intent. |
intrusive | Can take the service down. | Never launch on prod. |
dos | Takes the service down. | Forbidden outside the lab. |
Good practice: --script "safe and default" on a discovery scan. Targeted scripts (smb-vuln-*, http-shellshock, and so on) once you have a lead.
Bad practice: --script vuln on a wide sweep. You break things and you will not know which one.
7. Windows / SMB enumeration
On a Windows / Active Directory estate, the real gold mine is SMB (port 445) and LDAP (389, 636). The tools:
| Tool | What it does |
|---|---|
enum4linux-ng | Enumerates users, groups, shares, policy via a null session or with creds. |
smbclient -L //cible/ -N | Lists shares without authentication. |
crackmapexec smb <cible> | The SMB Swiss army knife: banner, shares, auth tests, remote execution. |
nxc smb <cible> | Maintained successor of crackmapexec (NetExec). |
smbmap -H <cible> -u <user> -p <pass> | Lists rights on each share. |
ldapsearch -x -H ldap://<cible> | Anonymous LDAP queries if allowed. |
What we look for:
- A null session (
-u '' -p '') that yields the user list = gold. - A readable
SYSVOLorNETLOGONshare with no password = abnormal, except on a DC. IPC$,ADMIN$,C$shares reachable with a standard domain account.- The password policy (length, expiry, lockout) — useful for password spraying later.
8. Wireshark — verify what you actually emit
Wireshark is not an offensive tool, strictly speaking. But a pentester who never uses it is a blind pentester.
Three uses:
- Verify your own traffic. Launch an
nmapand watch Wireshark: see how many packets you really send. Annmap -T4on a/24can send tens of thousands of SYN in 30 seconds. - Understand errors. A scan that returns
filtered— why? Is return ICMP blocked, or is the RST absorbed? - Find surprise protocols. A classic
nmapsees ports. Wireshark sees conversations — a chattymDNS, anLLMNRleft enabled, anElasticsearchthat answers in broadcast.
Filters to know by heart:
tcp.flags.syn == 1 and tcp.flags.ack == 0 # outbound SYN
tcp.flags.reset == 1 # RST received
smb2 # SMB2 traffic
dns.qry.name contains "internal" # suspicious DNS queries
9. Scapy — when nmap is no longer enough
Scapy is a Python library that lets you build a packet by hand, field by field. Useful when:
- You want to test a specific flag combination that
nmapdoes not offer natively. - You want to emit a single packet and see the reply in the clear.
- You want to build light protocol fuzzing.
The vital minimum:
from scapy.all import IP, TCP, UDP, ICMP, sr1
response = sr1(IP(dst="10.10.10.12") / TCP(dport=445, flags="S"), timeout=2, verbose=0)
if response and response.haslayer(TCP):
print("Flags received:", response[TCP].flags)
flags coming back:
0x12(SYN+ACK) → the port is open.0x14(RST+ACK) → the port is closed.None→ filtered.
You just wrote, in three lines, a port scan that bypasses the nmap signatures some IDS recognize. That is the power of Scapy.
10. The mistakes that cost
- Launching
-Afirst. You mix discovery, versions, OS, scripts and traceroute. You no longer know what comes from where. Work in layers. - Trusting the first scan. A port can be
filteredbecause of a transient IPS. Rerun, correlate. - Forgetting UDP. You miss SNMP, IKE, SIP, TFTP — services that often hold the key.
- Not capturing. Always record results with
-oA <prefix>. The.xmlfile feedsmsfconsole → db_import. - Scanning at night on a corporate LAN. The SOC does not sleep. Warn the escalation contact first.
- Using a single IP address. An IP burned at the start of the engagement = a slowed engagement. Plan a fallback (VPN, second interface).
11. What to remember
- Active = packets at the target. Register that mentally on every command.
- Scan in layers: discovery → ports → versions → targeted NSE.
- Six port states. Each one tells a story.
-T3by default,-sSby default. We tune after that.- NSE:
safeby default,vulnonly on identified targets,intrusivenever without a plan. - SMB is the Windows gold mine — learn
nxc smbby heart. - Wireshark to understand, Scapy to build.
Next lesson: we take the week 1 lab back, we add a second Linux victim, and we map everything, cleanly.