Eumeration
Enumerate material found on the machine.
Use pre-installed tools on the machine
Use scripting techniques
Use local tools through a proxy (last resort ; very slow)
Check arp cache, static mappings, local DNS servers and interfaces (Linux)
arp -a
cat /etc/hosts
cat /etc/resolv.conf
ip aCheck arp cache, static mappings and interfaces (Windows)
arp -a
type C:\Windows\System32\drivers\etc\hosts
ipconfig /allLiving Off the Land (LotL)
Start off with uploading nmap and scanning the network from the compromised server
./nmap -sn 10.200.72.0/24 -oN hostsBash one-liner ping sweep
Bash one-liner port scan
Windows ping sweep tools
Last updated
Was this helpful?