Chapter 3 · Fall 2026 edition · Slides

Network Reconnaissance

Learning objectives

  1. OBJ.01Distinguish passive from active reconnaissance
  2. OBJ.02Plan a scan inside an authorized scope
  3. OBJ.03Interpret port states and service banners

3.1 Mapping before touching

Every operation starts with a picture of the terrain. Passive collection builds that picture without sending a single packet to the target: DNS records, certificate transparency logs, job postings, and public code. Active scanning confirms and sharpens it, at the cost of being seen.

Passive collection asks third parties. Active scanning talks to the target.

3.2 Scoping the scan

Before any packet leaves your machine, write down what you are allowed to touch: the address ranges, the hours, and who to call if something breaks. A scan that is technically perfect but out of scope is still a failure.

# SYN scan with version detection, saved in all output formats
nmap -sS -sV -T3 -oA scans/lab-net 10.10.20.0/24

3.3 Reading port states

A SYN scan sends the first packet of a TCP handshake and judges the port by the reply.

sequenceDiagram
    accTitle: SYN scan port states
    accDescr: The scanner sends SYN. A SYN-ACK reply means open, and the scanner resets the connection. An RST reply means closed. No reply means filtered.
    participant S as Scanner
    participant T as Target port
    S->>T: SYN
    alt open
        T-->>S: SYN/ACK
        S->>T: RST (never completes the handshake)
    else closed
        T-->>S: RST
    else filtered
        Note over S,T: no reply (or ICMP unreachable)
    end
How a SYN scan classifies a port from the reply it gets.
StateReply to SYNWhat it tells you
openSYN/ACKA service is listening
closedRSTHost is reachable, nothing listening
filterednone, or ICMP unreachableSomething in the path is dropping probes