Looking for Network Activity (Advanced NMAP Techniques)
Vinny Troia · 2020
This chapter focuses on identifying active hosts and ports using advanced NMAP scanning techniques. Ndiff is specifically designed to show the differences between NMAP results. Rather than rehash the basics of performing NMAP scans, the chapter also focuses on several advanced use cases and techniques that the author has used to discover host activity, even through the most challenging firewalls. Any modern firewall or intrusion detection system (IDS) will come with a huge list of preconfigured block rules intended to block or minimize a person's ability to scan their infrastructure. If the traffic is not being blocked outright by a firewall, there is a possibility that it is being monitored by an IDS. The chapter provides guides to help circumvent detection by these systems.