EC-Council Certified Ethical Hacker (CEH) v12Reconnaissance TechniquesMedium

A security consultant is performing an internal penetration test and has gained a foothold on a Windows workstation. To identify other active hosts on the local subnet for lateral movement, without relying on tools that might be flagged by antivirus, which native Windows command-line utility could be used for basic host discovery?

  1. A`ipconfig /all`
  2. B`arp -a`
  3. C`netstat -ano`
  4. D`tasklist /svc`
Show answer & explanation

Correct answer: B. `arp -a`

The `arp -a` command displays the Address Resolution Protocol (ARP) cache, showing IP-to-MAC address mappings for devices that the workstation has recently communicated with on the local network. This is a native, stealthy way to identify active hosts on the same subnet without triggering antivirus.

Why the other options are wrong

  • A. `ipconfig /all` displays network configuration details of the local machine, not other hosts.
  • C. `netstat -ano` shows active network connections and listening ports on the local machine, not other hosts on the subnet.
  • D. `tasklist /svc` lists running processes and their associated services on the local machine.

ARP Cache for Host Discovery

The ARP (Address Resolution Protocol) cache stores mappings between IP addresses and MAC addresses of devices on the local network that a system has recently communicated with.

  • Accessed via `arp -a` on Windows/Linux.
  • Provides a list of live hosts that have communicated with the compromised machine.
  • A passive and native way to discover local network hosts.

Memory trick: ARP's cache remembers who's local, even when others forget.

More Reconnaissance Techniques questions