Network
Decision Tree: External Access Only → What First?
reference
- Recon
- Enumerate
- Foothold
- PrivEsc
- Lateral
- Post-Ex
The most common start: a target IP or a range in scope and nothing else in hand. Work it in this order and never skip the enumeration.
start Unauthenticated, external only, no creds yet
- 1Host Discovery (find every live host on the range)
- 2Full Nmap Strategy (every open port, with service and version)
- 3Service Enumeration Deep Dive (dig each service for the way in)
- any anonymous access, default creds, or exposed admin panel?
- 4Vulnerability Research Workflow (map the versions to known CVEs)
- 5Exploitation Examples (turn the best finding into a foothold)