[ftp] # 20, 21 nmap-service-names = [ "ftp", "ftp-data" ] recommendations = [ # none ] [ftp.scans] nmap = "nmap -vv -Pn -p --script=ftp-anon,ftp-bounce,ftp-libopie,ftp-proftpd-backdoor,ftp-syst,ftp-vsftpd-backdoor,ftp-vuln-cve2010-4221 -oN " [ssh] # 22 nmap-service-names = [ "ssh" ] recommendations = [ # none ] [ssh.scans] nmap = "nmap -vv -Pn -p --script=ssh2-enum-algos,ssh-hostkey,ssh-auth-methods -oN " [telnet] # 23 nmap-service-names = [ "telnet" ] recommendations = [ "telnet " ] [telnet.scans] nmap = "nmap -vv -Pn -p --script=telnet-encryption,telnet-ntlm-info -oN " [smtp] # 25 nmap-service-names = [ "smtp" ] recommendations = [ "telnet " ] [smtp.scans] nmap = "nmap -vv -Pn -p --script=smtp-ntlm-info,smtp-vuln-cve2010-4344,smtp-vuln-cve2011-1720,smtp-vuln-cve2011-1764 -oN " smtpuserenum = "smtp-user-enum -M VRFY -U -t 2>&1 | tee " [dns] # 53 nmap-service-names = [ "domain" ] recommendations = [ "nslookup" ] [dns.scans] dnsrecon = "dnsrecon -t axfr 2>&1 | tee " host = "host -t ns 2>&1 | tee " nmap = "nmap -v -Pn -p --script=dns-service-discovery,dns-cache-snoop,dns-check-zone,dns-zone-transfer -oN " [tftp] # 69 nmap-service-names = [ "tftp" ] recommendations = [ "tftp :" ] [tftp.scans] nmap = "nmap -vv -sU -Pn -p --script=tftp-enum -oN " [http] # 80, 591 nmap-service-names = [ "http", "http-alt" ] recommendations = [ "curl -v -X OPTIONS http://:/", "curl -v -X PUT -d '' http://://webshell.php", "dirb http://:/", "dotdotpwn -m http -h -x -f -k -d -t -s", "wafw00f http://://", "nmap -Pn -p --script http-adobe-coldfusion-apsa1301,http-coldfusion-subzero,http-vuln-cve2009-3960,http-vuln-cve2010-2861 -oN ", "wpscan --url http://:/", "wpscan --url http://:/ --enumerate vp" ] [http.scans] nikto = "nikto -host -port 2>&1 | tee " nmap = "nmap -vv -Pn -p --script=http-vuln* -oN " gobuster = "gobuster -e -w -u http://:/ 2>&1 | tee " [kerberos] nmap-service-names = [ "kerberos", "kerberos-sec" ] recommendations = [ # none ] [kerberos.scans] nmap = "nmap -vv -Pn -p --script=krb5-enum-users -oN " [https] # 443 nmap-service-names = [ "https", "ssl/http", "ssl/http-alt" ] recommendations = [ # none ] [https.scans] nikto = "nikto -host -port -ssl 2>&1 | tee " nmap = "nmap -vv -Pn -p --script=ssl-ccs-injection,ssl-cert,ssl-date,ssl-enum-ciphers,ssl-heartbleed,ssl-known-key,ssl-poodle -oN " gobuster = "gobuster -e -w -u https://:/ 2>&1 | tee " [pop3] # 110 nmap-service-names = [ "pop3" ] recommendations = [ "telnet " ] [pop3.scans] nmap = "nmap -vv -Pn -p --script=pop3-capabilities,pop3-ntlm-info -oN " [smb] # 139, 445 nmap-service-names = [ "microsoft-ds", "netbios-ssn" ] recommendations = [ "nmap -vv -sU --script=nbstat -p ", "crackmapexec smb -u -p --spider C\\$ --pattern ", "crackmapexec smb -u '' -p ''", "crackmapexec smb -u '' -p '' --local-auth", "smbclient -L ", "smbclient \\\\\\" ] [smb.scans] "nmap.tcp" = "nmap -vv -Pn -p --script smb-vuln* -oN " enum4linux = "enum4linux -a 2>&1 | tee " [imap] # 143, 220, 585, 993 nmap-service-names = [ "imap", "imap3", "imap4-ssl", "imaps" ] recommendations = [ "telnet " ] [imap.scans] nmap = "nmap -vv -Pn -p --script=imap-capabilities,imap-ntlm-info -oN " [msrpc] nmap-service-names = [ "epmap", "msrpc", "rpcbind", "sunrpc", "erpc" ] recommendations = [ "rpcclient -U '' ", "rpcinfo -p ", "showmount -e " ] [msrpc.scans] nmap = "nmap -vv -Pn -p --script=msrpc-enum -oN " [snmp] # 161 nmap-service-names = [ "snmp" ] recommendations = [ # none ] [snmp.scans] nmap = "nmap -vv -Pn -p --script=snmp-netstat,snmp-processes -oN " onesixtyone = "onesixtyone 2>&1 | tee " snmpwalk = "snmpwalk -c public -v1 2>&1 | tee " [ldap] # 389 nmap-service-names = [ "ldap" ] recommendations = [ # none ] [ldap.scans] enum4linux = "enum4linux -l 2>&1 | tee " [cups] nmap-service-names = [ "ipp" ] recommendations = [ # none ] [cups.scans] nmap = "nmap -vv -Pn -p --script=cups-info,cups-queue-info -oN " [rmi] # 1033 nmap-service-names = [ "java-rmi", "rmiregistry" ] recommendations = [ # none ] [rmi.scans] nmap = "nmap -vv -Pn -p --script=rmi-vuln-classloader,rmi-dumpregistry -oN " [mssql] # 1433, 1434 nmap-service-names = [ "ms-sql", "ms-sql-s" ] recommendations = [ "nmap -vv -Pn -p --script=ms-sql-dump-hashes --script-args='mssql.username=,mssql.password=,mssql.instance-port=' ", "nmap -vv -Pn -p --script ms-sql-xp-cmdshell --script-args='mssql.username=,mssql.password=,mssql.instance-port=,ms-sql-xp-cmdshell.cmd=\"\"' ", "sqsh -S : -U " ] [mssql.scans] nmap = "nmap -vv -Pn -p --script=ms-sql-config,ms-sql-dump-hashes,ms-sql-empty-password,ms-sql-info,ms-sql-ntlm-info,ms-sql-tables -oN " [oracle] # 1521 nmap-service-names = [ "oracle", "oracle-tns" ] recommendations = [ # none ] [oracle.scans] nmap = "nmap -vv -Pn -p --script=oracle-enum-users,oracle-tns-version -oN " [mysql] # 3306 nmap-service-names = [ "mysql" ] recommendations = [ "mysql -u root -proot " ] [mysql.scans] nmap = "nmap -vv -Pn -p --script=mysql-variables,mysql-vuln-cve2012-2122,mysql-info,mysql-users,mysql-enum,mysql-databases,mysql-dump-hashes -oN " [remotedesktop] # 3389 nmap-service-names = [ "ms-wbt-server", "msrdp" ] recommendations = [ "rdesktop -u Administrator -p administrator :" ] [remotedesktop.scans] nmap = "nmap -vv -Pn -p --script=rdp-enum-encryption,rdp-vuln-ms12-020 -oN " [vnc] nmap-service-names = [ "vnc" ] recommendations = [ # none ] [vnc.scans] nmap = "nmap -vv -Pn -p --script=vnc-info,vnc-title -oN "