3.1 Mapping before touching
Every operation starts with a picture of the terrain. Passive collection builds that picture without sending a single packet to the target: DNS records, certificate transparency logs, job postings, and public code. Active scanning confirms and sharpens it, at the cost of being seen.
3.2 Scoping the scan
Before any packet leaves your machine, write down what you are allowed to touch: the address ranges, the hours, and who to call if something breaks. A scan that is technically perfect but out of scope is still a failure.
# SYN scan with version detection, saved in all output formats
nmap -sS -sV -T3 -oA scans/lab-net 10.10.20.0/24
3.3 Reading port states
A SYN scan sends the first packet of a TCP handshake and judges the port by the reply.
sequenceDiagram
accTitle: SYN scan port states
accDescr: The scanner sends SYN. A SYN-ACK reply means open, and the scanner resets the connection. An RST reply means closed. No reply means filtered.
participant S as Scanner
participant T as Target port
S->>T: SYN
alt open
T-->>S: SYN/ACK
S->>T: RST (never completes the handshake)
else closed
T-->>S: RST
else filtered
Note over S,T: no reply (or ICMP unreachable)
end| State | Reply to SYN | What it tells you |
|---|---|---|
| open | SYN/ACK | A service is listening |
| closed | RST | Host is reachable, nothing listening |
| filtered | none, or ICMP unreachable | Something in the path is dropping probes |