Enumeration is the most critical part of all. The art, the difficulty, and the goal are not to gain access to our target computer. Instead, it is identifying all of the ways we could attack a target we must find.

nmap

Nmap offers many different types of scans that can be used to obtain various results about our targets. Basically, Nmap can be divided into the following scanning techniques:

Syntax-> nmap <scan types> <options> <target>

For example, the TCP-SYN scan (-sS) is one of the default settings unless we have defined otherwise


Host Discovery

It is always recommended to store every single scan. This can later be used for comparison, documentation, and reporting

sudo nmap 10.129.2.0/24 -sn -oA tnet | grep for | cut -d" " -f5

Scanning Options	Description
**10.129.2.0/24**	Target network range.
**-sn	Disables** port scanning.
**-oA tnet**	Stores the results in all formats starting with the name 'tnet'.

Scan IP List

sudo nmap -sn -oA tnet -iL hosts.lst | grep for | cut -d" " -f5