EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesMedium

A red team operator has successfully gained initial access to a client's internal network via a phishing campaign. They now need to enumerate internal systems and identify potential targets for further exploitation. Which of the following techniques is most appropriate for discovering active hosts and open ports within the newly accessed internal network segment, without generating excessive noise?

  1. AARP Scan (Nmap -PR)
  2. BSYN Stealth Scan (Nmap -sS)
  3. CUDP Scan (Nmap -sU)
  4. DFull TCP Connect Scan (Nmap -sT)
Show answer & explanation

Correct answer: B. SYN Stealth Scan (Nmap -sS)

A SYN stealth scan (Nmap -sS) is designed to be less intrusive and stealthier than a full TCP connect scan. It does not complete the three-way handshake, making it less likely to be logged by target systems and firewalls, which is crucial for a red team aiming to avoid detection.

Why the other options are wrong

  • A. ARP Scan is primarily for discovering hosts on the local subnet and doesn't reveal open ports on those hosts, which is a key requirement here.
  • C. UDP Scan can be slow and less reliable for host discovery, and often generates more traffic than a stealth SYN scan.
  • D. Full TCP Connect Scan completes the three-way handshake, which is noisy and easily logged by target systems.

SYN Stealth Scan (Nmap -sS)

A port scanning technique where the scanner sends a SYN packet and analyzes the target's response (SYN/ACK or RST) without completing the TCP three-way handshake, making it less detectable.

  • Also known as 'half-open' scanning.
  • Less likely to be logged by firewalls and intrusion detection systems.
  • Requires raw packet privileges (often root/administrator) to perform.

Memory trick: Scan choices: Connect is loud, SYN is sly, UDP for unknowns, ARP for nearby.

More System Hacking Phases and Attack Techniques questions