Operator tip · nmap
Host discovery first
On a flat lab net: nmap -sn 10.10.0.0/24 then target live hosts. Skip -Pn until you know ICMP is blocked.
Guide
Spraying a full port scan across a /24 before you know who is alive burns time and fills logs with dead hosts. Discover first, then focus.
Why it matters
Host discovery (-sn) is cheap. A live list lets you prioritize, name hosts in notes, and avoid treating broadcast/gateway noise as targets. -Pn skips discovery and assumes every IP is up — useful when ICMP is filtered, wasteful when it is not.
How-to
# Ping sweep (no port scan)
nmap -sn 10.10.0.0/24 -oG - | awk '/Up$/{print $2}'
# Then deep-scan only live hosts
nmap -sC -sV -p- -iL live.txt -oA recon/live
- On VPN/lab nets, try discovery without
-Pnfirst. - If nothing answers ICMP but you know a host exists, retry with
-Pnon that single IP. - Document the discovery method in your report — auditors care how you found the asset.
Examples
nmap -sn 10.10.11.0/24 # Up hosts → write live.txt → targeted -sC -sV