A structured lesson workspace with readable content, hands-on examples, and a clean path to completion.
You just ran Nmap against a /16 and got 340 hosts with web services. Opening each one in a browser is not a methodology. EyeWitness and Aquatone solve this by screenshotting every web service and assembling an HTML report you can triage visually.
EyeWitness categorizes results automatically. High Value Targets appear first—Tomcat managers, Jenkins consoles, admin panels. It fingerprints applications and suggests default credentials. For a 26-host scope, this saves an hour. For 500 hosts, it saves a day.
Tomcat on any assessment means try default credentials on /manager and /host-manager immediately. A support portal running osTicket means potential email address harvesting. A GitLab instance means check for open registration and public repos. Custom applications with file upload buttons mean test unrestricted upload.
During an external pentest, a ManageEngine OpManager instance was found buried deep in a massive EyeWitness report. Default credentials admin:admin. The application ran as Domain Admin. Full internal compromise from one overlooked screenshot on page 47.
Don't start attacking hosts the moment you see them. Complete the entire report review first. Note every interesting host with URL, application name, and version. Then attack systematically. Rabbit holes kill engagements.
EyeWitness reports in large environments can exceed 500 pages. Interesting hosts get buried. Review the entire report. The OpManager find on page 47 proved that.
Finish the lesson once you have worked through the material. This awards ★ 20 XP.