Network Enumeration with Nmap Easy
Nmap is one of the most used networking mapping and discovery tools because of its accurate results and efficiency. The tool is widely used by both offensive and defensive security practitioners. This module covers fundamentals that will be needed to use the Nmap tool for performing effective network enumeration.
Created by Cry0l1t3
Nmap is used to identify and scan systems on the network. It is an important part of network diagnostics and evaluation of network-connected systems. In this module, we will learn the basics of this tool and how it can be used efficiently to map out the internal network by identifying live hosts and performing port scanning, service enumeration, and operating system detection.
In this module, we will cover:
- An overview of Nmap
- Host discovery and port scanning
- Saving scan results
- Service enumeration
- Using the powerful Nmap scripting language
- Firewall and IDS/IPS evasion
This module is broken down into sections with accompanying hands-on exercises to practice each of the tactics and techniques we cover. The module ends with three hands-on labs of increasing difficulty to gauge your understanding of the various topic areas.
As you work through the module, you will see example commands and command output for the various topics introduced. It is worth reproducing as many of these examples as possible to reinforce further the concepts introduced in each section. You can do this in the Pwnbox provided in the interactive sections or your own virtual machine.
You can start and stop the module at any time and pick up where you left off. There is no time limit or "grading," but you must complete all of the exercises and the labs to receive the maximum number of cubes and have this module marked as complete in any paths you have chosen.
The module is classified as "Easy" but assumes a working knowledge of the Linux command line and an understanding of information security fundamentals.
A firm grasp of the following modules can be considered prerequisites for successful completion of this module:
- Introduction to Networking
- Linux Fundamentals
- Introduction to Nmap
- Host Discovery
- Host and Port Scanning
- Saving the Results
- Service Enumeration
- Nmap Scripting Engine
- Firewall and IDS/IPS Evasion
- Firewall and IDS/IPS Evasion - Easy Lab
- Firewall and IDS/IPS Evasion - Medium Lab
- Firewall and IDS/IPS Evasion - Hard Lab
This module progresses you towards the following Paths
Medium 76 Sections
Cubes Required: 370
In this path, modules cover the basic tools needed to be successful in network and web application penetration testing. This is not an exhaustive listing of all tools (both open source and commercial) available to us as security practitioners but covers tried and true tools that we find ourselves using on every technical assessment that we perform. Learning how to use the basic toolset is essential, as many different tools are used in penetration testing. We need to understand which of them to use for the various situations we will come across.
Easy 12 Sections
Nmap is one of the most used networking mapping and discovery tools because of its accurate results and efficiency. The tool is widely used by both offensive and defensive security practitioners. This module covers fundamentals that will be needed to use the Nmap tool for performing effective network enumeration.Login Brute Forcing
Easy 11 Sections
Learn how to brute force logins for various types of services and create custom wordlists based on your target.Attacking Web Applications with Ffuf
Easy 13 Sections
This module covers the fundamental enumeration skills of web fuzzing and directory brute forcing using the Ffuf tool. The techniques learned in this module will help us in locating hidden pages, directories, and parameters when targeting web applications.Cracking Passwords with Hashcat
Medium 14 Sections
This module covers the fundamentals of password cracking using the Hashcat tool.SQLMap Essentials
Easy 11 Sections
The SQLMap Essentials module will teach you the basics of using SQLMap to discover various types of SQL Injection vulnerabilities, all the way to the advanced enumeration of databases to retrieve all data of interest.Intro to Network Traffic Analysis
Medium 15 Sections
Network traffic analysis is used by security teams to monitor network activity and look for anomalies that could indicate security and operational issues. Offensive security practitioners can use network traffic analysis to search for sensitive data such as credentials, hidden applications, reachable network segments, or other potentially sensitive information "on the wire." Network traffic analysis has many uses for attackers and defenders alike.