Generic Hackingupdated Oct 1, 2026

Service & Content Enumeration

Post-recon runbook: port and service mapping, size-filtered content discovery, JS endpoint extraction, and technology fingerprinting to build a prioritized hit list.

toolbox:nmapffufgobusterkatananuclei

Once recon gives you a shortlist of live hosts, enumeration is where real vulnerability types start to surface. Goal: map every reachable service, file, and endpoint on in-scope hosts, and hand a prioritized inventory to the next phase. Assume all tools are installed and are tested only against authorized targets.

1. Port and service mapping

Start with a fast sweep, then drill into what is actually open. Never service-scan the full range — it is slow and noisy.

mkdir -p enum && cd enum

# Fast SYN sweep, no service probe
nmap -sS -p- --min-rate 4000 -T4 -oG ports.txt <target>

# Extract open ports, then run version + default scripts on just those
OPEN=$(grep -oP '\d+/open' ports.txt | cut -d/ -f1 | paste -sd,)
nmap -sV -sC -p "$OPEN" -T3 -oN services.txt <target>

Common high-value services to flag:

Port Service What to chase
6379 Redis unauthenticated access
27017 MongoDB open instance, collection dump
9200 Elasticsearch /_cat/indices data leak
2375 Docker host path disclosure
5984 CouchDB default admin patterns

2. Content discovery

Fuzz with a short wordlist first, baseline the wildcard response, then filter by size.

BASE=$(curl -s -o /dev/null -w '%{size_download}' https://target/nonexistent-xyz)

# Directory/file discovery, filtering wildcard size
ffuf -u https://target/FUZZ -w /wordlists/common.txt \
  -mc 200,201,204,301,302,307,401,403 -fs "$BASE" -t 64 -o ffuf-common.json

# Deeper wordlist once wildcard behavior is understood
ffuf -u https://target/FUZZ -w /wordlists/raft-large-words.txt \
  -mc 200,204 -fs "$BASE" -t 48 -o ffuf-deep.txt

# Extension brute-force on a discovered directory
gobuster dir -u https://target/ -w /wordlists/common.txt -x php,bak,zip,json -t 30 -o gobuster.txt

A 403 where nothing should exist is a hint; a 200 with an unexpected size is a finding.

3. Endpoint extraction from JS and history

# Crawl links, forms, and JS routes
katana -u https://target -d 3 -jc -ef pdf,png,jpg,svg -o crawl.txt

# Pull API-ish paths straight out of JS bundles
grep -ohE '"/(api|v[0-9]|rest|graphql)/[^"]+"' crawl.txt | tr -d '"' | sort -u > endpoints.txt

# Historical URLs often expose forgotten or pre-auth endpoints
gau target.com | grep -E '(/api/|\.json|\.xml)' | sort -u >> endpoints.txt
sort -u endpoints.txt -o endpoints.txt

Every new endpoint feeds the injection and auth phases. Group results by host in endpoints.txt.

4. Technology fingerprinting

Fingerprint before scanning — version banners decide which CVEs matter.

whatweb -i live.txt --log-brief=whatweb.txt
nuclei -l live.txt -tags tech -silent -o tech.txt

5. Full pipeline

mkdir -p enum && cd enum

nmap -sS -p- --min-rate 4000 -T4 -oG ports.txt <target>
OPEN=$(grep -oP '\d+/open' ports.txt | cut -d/ -f1 | paste -sd,)
nmap -sV -sC -p "$OPEN" -T3 -oN services.txt <target>

BASE=$(curl -s -o /dev/null -w '%{size_download}' https://target/nonexistent-xyz)
ffuf -u https://target/FUZZ -w /wordlists/common.txt -mc 200,201,204,301,302,307,401,403 -fs "$BASE" -t 64 -o ffuf-common.json
gobuster dir -u https://target/ -w /wordlists/common.txt -x php,bak,zip,json -t 30 -o gobuster.txt

katana -u https://target -d 3 -jc -ef pdf,png,jpg,svg -o crawl.txt
grep -ohE '"/(api|v[0-9]|rest|graphql)/[^"]+"' crawl.txt | tr -d '"' | sort -u > endpoints.txt
gau target.com | grep -E '(/api/|\.json|\.xml)' | sort -u >> endpoints.txt
sort -u endpoints.txt -o endpoints.txt

whatweb -i live.txt --log-brief=whatweb.txt
nuclei -l live.txt -tags tech -silent -o tech.txt

Ethics & legality

  • Only enumerate hosts inside an official scope or with written authorization.
  • Respect the agreed scan window and rate limits; throttle fuzzing on production.
  • Never run credential brute-force from this phase.
  • Log every command with timestamp so findings are defensible.