To conduct a penetration test we have to get an overview of which systems are online, and which ones we can work with.
Network Sweep
Use this when you have a CIDR range and need live hosts without scanning ports.
# scan a target network range without scanning ports (-sn) and storing the result in all formats starting with the name 'tnet'
sudo nmap $HOST/24 -sn -oA tnet | grep for | cut -d" " -f5Host List Sweep
Use a predefined host list when targets were gathered from OSINT, DNS, or prior enumeration.
# perform host discovery on a predefined list
sudo nmap -sn -oA tnet -iL hosts.lst | grep for | cut -d" " -f5ICMP Probe
ICMP echo requests can confirm a single host is alive when ICMP is allowed.
# check whether a single IP is alive using ICMP echo requests (-PE) and packet tracing for more verbose output
sudo nmap $HOST -sn -oA host -PE --packet-trace Routed Host Probe
Disable ARP pings when scanning across routers because ARP is local-only.
# check whether a single IP is alive without using ARP pings
sudo nmap $HOST -sn -oA host -PE --packet-trace --disable-arp-ping Some options during scanning can have advantages:
- Disable DNS Resolution saves time by skipping reverse DNS lookups
- Disable ARP Ping is better because ARP is local-only, if you’re scanning across routers ARP won’t work.
- Disable ICMP echo requests is better for evasion because modern networks will block or alert on ICMP.