Lesson 1 of 4
Discovery, and the inventory that is always wrong
Several incomplete sources, compared — the hosts in only one of them are the interesting ones.
14 min 3-question quiz 3 guides to read next
On this page
Every infrastructure assessment starts with the same finding: the network contains things nobody listed.
Use several sources
No single source is complete, and each is incomplete differently:
- The asset inventory, which reflects what people remembered to record.
- Address allocations and DHCP, which show what was assigned, not what is live.
- DNS, including internal zones, which holds names for things long gone and things never documented.
- Cloud provider APIs, authoritative for the accounts you know about — so start from billing, which knows about all of them.
- Directory and endpoint management, which knows about managed machines and says nothing about the unmanaged ones.
- Active probing, which finds what is live and misses what is off today.
Compare them. Hosts appearing in only one source are the interesting ones: the unmanaged device, the forgotten virtual machine, the system whose owner left.
Enumerate carefully
For each live host: what is listening, what software and version, how is it authenticated, and who owns it. Treat version banners as hints — services misreport, and backported patches make versions misleading on long-term-support distributions. Verify before reporting.
Look here first
Management interfaces exposed beyond their intended network — hypervisors, out-of-band management, printers, building systems, databases. Default or shared credentials, which remain the most reliable way into an internal network. Legacy protocols still enabled. Forgotten environments: staging with production data, a test domain the real one trusts.
The output
Not a port list. A list of owned things, each with a purpose and a person — plus the list with no owner, which is where the next incident starts.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Network Discovery and Service Enumeration
Finding what is actually listening, and why the inventory is always wrong.
2 min read
-
Attack Surface Discovery: DNS, Certificates and Cloud
Finding the internet-facing things you own, including the ones nobody remembers creating.
2 min read
-
Shadow IT and Unmanaged Assets
The systems nobody told you about, why they appear, and how to find them without becoming the enemy.
2 min read