A structured lesson workspace with readable content, hands-on examples, and a clean path to completion.
Seven ports. That's your starting set. Ports 80, 443, 8000, 8080, 8180, 8888, and 10000 catch the vast majority of web applications in corporate environments. The -oA flag saves output in all three formats—normal, XML, and grepable—because you'll need the XML for screenshotting tools later.
Look at those FQDNs. Anything with dev in the name is worth flagging immediately. Development hosts run untested features, debug modes, and forgotten admin panels. gitlab-dev.inlanefreight.local might have public repos with hardcoded credentials. jenkins-dev might allow anonymous access.
10.129.201.50 shows ports 135, 139, 445, 3389 alongside 8000 and 8080. That's Windows. Port 8089 screams Splunk management API. Port 8080 with the right service banner could be PRTG. You're already building a mental map before touching a browser.One scan just handed you three applications: IIS on 80, Splunk on 8000/8089, and PRTG on 8080. The Splunk banner says free license with remote login disabled—that means no authentication required. You just found your foothold without sending a single exploit.
Running -sV against every host in a 500-host scope is inefficient and noisy. Use the initial port scan to identify web services, then run service detection only against hosts that actually interest you. Enumeration is iterative, not exhaustive.
Set up your hosts file before moving forward. Vhosts won't resolve without manual entries, and you'll waste twenty minutes wondering why curl returns nothing.
Now you have structured scan data, identified high-value targets, and your hosts file is configured. Next step: turn those raw IPs into visual screenshots you can triage in minutes instead of hours.
Finish the lesson once you have worked through the material. This awards ★ 20 XP.