Every network assessment starts with the same uncomfortable discovery: the network contains things nobody listed.
Discovery
Start from authoritative sources — address allocations, DHCP, cloud provider APIs, DNS zones, certificate transparency logs — then verify by probing. Each source is incomplete in a different way, which is why you use several and compare. The devices that appear in only one source are the interesting ones.
Enumeration
For each live host, the questions are: what is listening, what software and version, how is it authenticated, and who owns it. Version information from banners is a hint, not a fact; services misreport, and backported patches make version strings misleading on long-term-support distributions.
What to look for first
- Management interfaces exposed beyond their intended network: hypervisors, out-of-band management, printers, building systems, databases.
- Default and shared credentials, which remain the most reliable route into an internal network.
- Legacy protocols still enabled: unauthenticated file sharing, cleartext administration, old TLS.
- Forgotten environments: staging with production data, a test domain trusted by the real one.
The output that matters
Not a list of ports. A list of owned things, each with a service, a business purpose and a person — plus a list of things with no owner, which is where the next incident will start.