Festival Season Offer15% off on all our programmes — claim it before you enrol
MODULE 2 OF 6  ·  30 Hrs  ·  3 Weeks

Reconnaissance, Scanning & Enumeration

Before any system is exploited, it has to be understood. This module builds the reconnaissance and enumeration discipline that separates a structured assessment from guesswork — profiling targets, mapping attack surfaces and scoring what's actually exploitable.

Who This Module Is For
Students who have completed the foundations module and are ready to run structured, tool-driven assessments against lab infrastructure.
Real-World Relevance
Reconnaissance and vulnerability scoring are the first deliverables on almost every real penetration test and vulnerability-assessment engagement — and the skill most directly tested in SOC and VAPT interviews.
Program OverviewView Hands-On Labs
Curriculum

What You Will Learn

A detailed, industry-aligned breakdown of every topic covered in this module.

  • Introduction to reconnaissance and intelligence-gathering methodology
  • Open-source intelligence (OSINT) techniques and tradecraft
  • WHOIS lookups, domain registration analysis and DNS enumeration
  • Passive vs active reconnaissance — when and how to use each
  • Port scanning fundamentals and advanced scanning techniques (SYN, stealth, UDP)
  • Technology stack identification and service/version fingerprinting
  • FTP, SMTP and SMB enumeration techniques
  • Email discovery and verification techniques
  • Vulnerability assessment using automated scanning tools
  • Reading and scoring vulnerability records with CVE, CVSS and CWE
  • Using the NIST and NVD vulnerability databases inside an assessment
  • Building an attack-surface map from reconnaissance data
  • Documenting reconnaissance findings in a client-ready format
Technology Stack

Tools You Will Use

Hands-on time with the same tools used in professional security operations and penetration-testing engagements.

Nmap

Network mapping and port-scanning engine used to discover hosts, services and open ports.

OpenVAS

Open-source vulnerability scanner used to identify and score security weaknesses across a target estate.

Maltego

OSINT and link-analysis platform used to map relationships between people, domains and infrastructure.

Netcat

Networking utility used for port testing, banner grabbing and building lightweight listeners during engagements.

Kali Linux

Debian-based penetration testing distribution preloaded with the industry-standard offensive security toolset.

Practical Work

Hands-On Labs

Enterprise and SOC-style lab scenarios, run inside your isolated penetration-testing environment.

01

Run an OSINT investigation against a lab-provided target domain.

02

Perform a full port scan and service fingerprint of a segmented lab network using Nmap.

03

Run an automated vulnerability scan with OpenVAS and triage results by CVSS score.

04

Enumerate SMB and FTP services against a vulnerable lab server.

05

Build an attack-surface map and deliver a written reconnaissance findings report.

Evaluation

Assessment

Knowledge Assessment

Quiz covering OSINT methodology, scanning technique selection and CVE/CVSS/CWE scoring.

Practical Evaluation

Students must produce a scan report identifying the open services and vulnerabilities on an assigned lab target, each correctly scored against CVSS.

Portfolio

Projects

Industry-style deliverables added directly to your project portfolio.

Portfolio Project 01

Reconnaissance & Vulnerability Assessment Report

OSINT, scanning and enumeration against a lab target, documented and mapped to CVE/CVSS/CWE standards.

Portfolio Project 02

Attack Surface Mapping Dashboard

A structured, visual record of a target's exposed assets, services and entry points.

Portfolio Project 03

Email & Domain Intelligence Brief

An OSINT-based reconnaissance dossier on a lab-safe target organisation.

Module Outcome

What This Module Builds

Students learn to profile targets, map attack surfaces and identify exploitable vulnerabilities using industry-standard scanning methodology.

Maps to job roles
SOC AnalystVulnerability AssessorJunior Penetration TesterThreat Intelligence Analyst

Continue building your cybersecurity portfolio

Next up: Module 3 — System Hacking, Malware & Social Engineering

Go to Module 3Full Roadmap