Reconnaissance, Scanning & Enumeration
Before any system is exploited, it has to be understood. This module builds the reconnaissance and enumeration discipline that separates a structured assessment from guesswork — profiling targets, mapping attack surfaces and scoring what's actually exploitable.
What You Will Learn
A detailed, industry-aligned breakdown of every topic covered in this module.
- Introduction to reconnaissance and intelligence-gathering methodology
- Open-source intelligence (OSINT) techniques and tradecraft
- WHOIS lookups, domain registration analysis and DNS enumeration
- Passive vs active reconnaissance — when and how to use each
- Port scanning fundamentals and advanced scanning techniques (SYN, stealth, UDP)
- Technology stack identification and service/version fingerprinting
- FTP, SMTP and SMB enumeration techniques
- Email discovery and verification techniques
- Vulnerability assessment using automated scanning tools
- Reading and scoring vulnerability records with CVE, CVSS and CWE
- Using the NIST and NVD vulnerability databases inside an assessment
- Building an attack-surface map from reconnaissance data
- Documenting reconnaissance findings in a client-ready format
Tools You Will Use
Hands-on time with the same tools used in professional security operations and penetration-testing engagements.
Nmap
Network mapping and port-scanning engine used to discover hosts, services and open ports.
OpenVAS
Open-source vulnerability scanner used to identify and score security weaknesses across a target estate.
Maltego
OSINT and link-analysis platform used to map relationships between people, domains and infrastructure.
Netcat
Networking utility used for port testing, banner grabbing and building lightweight listeners during engagements.
Kali Linux
Debian-based penetration testing distribution preloaded with the industry-standard offensive security toolset.
Hands-On Labs
Enterprise and SOC-style lab scenarios, run inside your isolated penetration-testing environment.
Run an OSINT investigation against a lab-provided target domain.
Perform a full port scan and service fingerprint of a segmented lab network using Nmap.
Run an automated vulnerability scan with OpenVAS and triage results by CVSS score.
Enumerate SMB and FTP services against a vulnerable lab server.
Build an attack-surface map and deliver a written reconnaissance findings report.
Assessment
Knowledge Assessment
Quiz covering OSINT methodology, scanning technique selection and CVE/CVSS/CWE scoring.
Practical Evaluation
Students must produce a scan report identifying the open services and vulnerabilities on an assigned lab target, each correctly scored against CVSS.
Projects
Industry-style deliverables added directly to your project portfolio.
Reconnaissance & Vulnerability Assessment Report
OSINT, scanning and enumeration against a lab target, documented and mapped to CVE/CVSS/CWE standards.
Attack Surface Mapping Dashboard
A structured, visual record of a target's exposed assets, services and entry points.
Email & Domain Intelligence Brief
An OSINT-based reconnaissance dossier on a lab-safe target organisation.
What This Module Builds
Students learn to profile targets, map attack surfaces and identify exploitable vulnerabilities using industry-standard scanning methodology.
