Scanning
Almost always scan this first.
Then once I have a baseline I start all ports.
Or this if I feel good about ports already found.
Got to scan UDP sometimes!
I'll run autorecon generically or variations of no ping and slowing down if there's some issues. Or just reset the machine if it's a CTF.
See port enum pages for individual nmap scans targetting a spcific port!
Don't neglect the nse scripts, especially, ftp, smb, smtp, and http. It's worth it! Though autorecon usually tries these.
Scanning Through Proxychains (pivot point)
Specify the port and always do -sT -Pn so it doesn't use icmp and only TCP scans
Last updated