Active Recon
- Discover all active hosts on the target IP Range/Subnets
- [ ] Nmap Host Discovery Scan
- [ ] ICMP sweep Ping
- [ ] TCP/UDP Host discovery
- [ ] ARP Scanning
- For all active hosts Scan for TCP/UDP Ports
- For each port run service scan on discovered ports
- Check for vulnerability in discovered services/service version
- [ ] Search
metaspsloit for service exploits with the discovered version
- [ ] Search
ExploitDB for service exploits with the discovered version