Skip to content

Network Discovery and Service Enumeration

Finding what is actually listening, and why the inventory is always wrong.

Editorial team 2 min read

Every network assessment starts with the same uncomfortable discovery: the network contains things nobody listed.

Discovery

Start from authoritative sources — address allocations, DHCP, cloud provider APIs, DNS zones, certificate transparency logs — then verify by probing. Each source is incomplete in a different way, which is why you use several and compare. The devices that appear in only one source are the interesting ones.

Enumeration

For each live host, the questions are: what is listening, what software and version, how is it authenticated, and who owns it. Version information from banners is a hint, not a fact; services misreport, and backported patches make version strings misleading on long-term-support distributions.

What to look for first

  • Management interfaces exposed beyond their intended network: hypervisors, out-of-band management, printers, building systems, databases.
  • Default and shared credentials, which remain the most reliable route into an internal network.
  • Legacy protocols still enabled: unauthenticated file sharing, cleartext administration, old TLS.
  • Forgotten environments: staging with production data, a test domain trusted by the real one.

The output that matters

Not a list of ports. A list of owned things, each with a service, a business purpose and a person — plus a list of things with no owner, which is where the next incident will start.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025