7.1 Network Reconnaissance, Unauthorized Access, and Port Scanning

Key Takeaways

  • Passive reconnaissance leverages OSINT, search engines (Shodan, Censys), and public DNS records without sending traffic directly to target networks, whereas active reconnaissance directly interacts with target boundaries via ping sweeps, port scans, and DNS zone transfer queries (AXFR).

  • TCP SYN scans (-sS) send RST after SYN-ACK instead of completing the handshake; TCP Connect scans (-sT) complete the connection and are more likely to produce application or service logs, though logging depends on the target and configuration.

  • Inverted and stealth scans—such as FIN (-sF), Xmas (-sX), and NULL (-sN) scans—exploit RFC 793 stipulations where closed ports return RST packets while open ports silently drop unexpected flag combinations, though Windows and Cisco network stacks deviate from RFC 793 by returning RSTs regardless of port state.

  • Unauthorized access techniques are differentiated by their operational methodology: brute-force attacks exhaustively test thousands of passwords against a single account, credential stuffing replays compromised credentials from public breaches, and password spraying tests a few common passwords against thousands of accounts to bypass lockout thresholds.

  • Network anomaly detection correlates NetFlow/IPFIX telemetry for volume/flow deviations with deep packet inspection platforms like Zeek (for detailed protocol connection logs) and Suricata/Snort (for signature-based alerts on port scanning and rapid authentication failures).

Last updated: October 2026

Network Reconnaissance, Unauthorized Access, and Port Scanning

Network perimeters are a major enterprise attack surface. Many intrusions include reconnaissance or scanning, but attackers can also use known targets, stolen credentials, trusted relationships, or pre-positioned access without observable scanning. For incident handlers, identifying preparatory indicators, dissecting port probes, distinguishing credential attack patterns, and detecting baseline traffic deviations are essential competencies.

Network Attack Surface and Reconnaissance Techniques

Reconnaissance allows adversaries to map infrastructure, address allocations, and listening services:

  • Passive Reconnaissance: Intelligence gathering without transmitting packets directly to target systems, generating no firewall or IDS alerts. Threat actors utilize Open-Source Intelligence (OSINT), querying WHOIS registries, examining Certificate Transparency logs via crt.sh, and mining passive DNS records. Adversaries leverage search engines like Shodan and Censys to index open ports, banners, TLS certificates, and device types, discovering exposed management consoles or unpatched appliances out-of-band.
  • Active Reconnaissance: Probing boundary routers, firewalls, and hosts directly to elicit responses, providing concrete data regarding active hosts and network topology. A prime active vector is the DNS Zone Transfer (AXFR). DNS servers utilize AXFR queries over TCP port 53 to replicate zone data between authoritative servers. When left unrestricted, an adversary executes an AXFR query (via dig) to download the complete zone database, obtaining the names and records exposed by that zone; this may reveal valuable addressing and service clues but not necessarily the complete internal topology.

Scanning Methodologies and Protocol Mechanics

Adversaries deploy scanners like Nmap to locate responsive hosts and inspect port states via distinct transport mechanics:

  • Ping Sweeps: Scanners verify host vitality before port enumeration. Standard sweeps send ICMP Echo Requests (Type 8) expecting Echo Replies (Type 0). Because firewalls frequently filter ICMP, scanners deploy TCP discovery (SYN to port 443, ACK to port 80) or local Layer 2 ARP sweeps that bypass host firewalls.
  • TCP SYN Stealth Scans (-sS): Termed half-open scanning, the TCP SYN scan is Nmap's default technique. The scanner transmits a SYN segment. If open, the target returns SYN-ACK; the scanner replies with RST rather than completing the handshake with an ACK. This half-open state usually prevents delivery to the listening application and often avoids full-connection service logs, while remaining visible to host, firewall, and network sensors. Closed ports return RST-ACK.
  • TCP Connect Scans (-sT): When lacking raw socket privileges, the scanner invokes the operating system connect() call, completing the full three-way handshake (SYN -> SYN-ACK -> ACK) before teardown. Because the socket is fully established, application services log the connection event, making -sT significantly noisier.
  • Inverted and Stealth Scans (FIN, Xmas, NULL): Under RFC 793, closed ports return RST-ACK to unexpected packets, while open ports drop them silently. A FIN scan (-sF) sets only FIN, an Xmas scan (-sX) sets FIN, PSH, and URG, and a NULL scan (-sN) clears all flags. While BSD Unix and Linux follow RFC 793, Windows and Cisco IOS return RST-ACK regardless of port state, rendering inverted scans ineffective against Windows.
  • UDP Scans (-sU): Because UDP is connectionless, the scanner sends UDP probes to target ports. Closed ports elicit an ICMP Type 3, Code 3 (Port Unreachable) error, while open ports return application data or drop probes silently (open|filtered). Because kernels rate-limit ICMP unreachable generation, UDP scanning across large port ranges is exceptionally slow.

Nmap Flags and Detection Signatures in IDS/IPS

Incident handlers must correlate operational scanner flags with network intrusion detection signatures:

  • Nmap Flags: Timing templates range from -T0 (Paranoid) to -T5 (Insane). Evasion options include packet fragmentation (-f), custom MTU sizing (--mtu 16), decoy generation (-D RND:10), and source port spoofing (-g 53 or --source-port 88) to bypass legacy firewall rules permitting inbound traffic from DNS or Kerberos ports.
  • IDS/IPS Signatures: Snort and Suricata detect scanning via protocol anomaly rules and preprocessors. An Xmas scan rule inspects raw TCP flags: alert tcp any any -> $HOME_NET any (msg:"SCAN Xmas Scan"; flags:FPU; classtype:attempted-recon; sid:1000001; rev:1;). Stream preprocessors (like Snort's sfPortscan) track unique destination ports per source host over sliding time windows, alerting when thresholds are exceeded (e.g., 20 ports within 5 seconds).

Unauthorized Access Detection and Credential Attacks

Following port discovery, adversaries target administrative services (SSH on TCP 22, RDP on TCP 3389, SMB on TCP 445, WinRM on TCP 5985/5986):

  • Brute-Force Attacks: Exhaustively testing thousands of passwords against a single targeted account (e.g., administrator or root), generating rapid failed authentications that trigger lockout thresholds.
  • Credential Stuffing: Automated replaying of exfiltrated credentials from public breaches across enterprise SSO, VPN, or web portals, capitalizing on password reuse.
  • Password Spraying: Horizontal testing of one or two common passwords (e.g., Autumn2026!) across thousands of enterprise user accounts, spacing attempts across hours to evade per-account lockout thresholds.
  • Authentication Telemetry: Correlating host security logs is essential. In Windows, handlers inspect Security event logs: Event ID 4625 denotes failed logons, Event ID 4624 records successful logons (Logon Type 3 for network/SMB and Logon Type 10 for RDP), and Event ID 4740 records account lockouts. On Linux, /var/log/auth.log or /var/log/secure captures failed passwords and invalid user attempts via sshd.

Network Baseline Deviations and Anomaly Detection

Early detection of reconnaissance and unauthorized access relies on identifying statistical deviations in network flow data and transaction logs:

  • NetFlow and IPFIX Telemetry: NetFlow/IPFIX records unidirectional flow summaries (IPs, ports, protocols, packet/byte counts, flow duration). Port scanning manifests as an extreme anomaly: a dramatic spike in flow records with minimal packets per flow (1-2 packets), tiny byte volumes (<100 bytes), short lifetimes (<50 milliseconds), and a high fan-out ratio (one source querying hundreds of unique destination ports or IPs).
  • Zeek Connection Logs: Zeek captures connection states in its conn.log history field. S0 denotes a SYN probe sent with no response received (filtered/dropped), Sr indicates a SYN followed by an immediate RST (closed port), and ShADdFf denotes a normal completed TCP session.
  • SIEM Correlation: SIEM platforms correlate NetFlow spikes with Zeek S0 connection histories and host authentication failures (Event ID 4625 clusters), isolating reconnaissance and credential attacks before lateral movement begins.
Loading diagram...
TCP Port Scan Signatures: SYN vs Connect vs Inverted Scans
Test Your Knowledge

An incident handler analyzes firewall and network packet captures during an investigation of external scanning activity. The telemetry reveals thousands of incoming TCP packets directed at sequential ports on a perimeter server. For ports running active services, the target server responded with a TCP packet containing the SYN and ACK flags, immediately followed by a packet from the external scanner with the RST flag set. No corresponding connection events were recorded in the server's application-level service logs. Which scanning technique was the attacker executing?

A

A TCP SYN scan (-sS) that terminates before the three-way handshake completes, explaining the absence of a full-connection application log in this scenario

B

A TCP Connect scan (-sT) that fully establishes the socket before issuing an operating system teardown

C

A UDP scan (-sU) that relies on ICMP Port Unreachable error messages to infer port state

D

An inverted Xmas scan (-sX) that illuminates the FIN, PSH, and URG control flags to bypass stateful firewalls

Test Your Knowledge

During a security monitoring shift, a Security Operations Center (SOC) analyst investigates an alert triggering on Active Directory domain controllers. Over a 30-minute period, 1,200 distinct enterprise user accounts experienced exactly one failed logon attempt (Event ID 4625) originating from an internal compromised workstation, all utilizing the same candidate password string. None of the user accounts reached the corporate account lockout threshold of five failed attempts. Which unauthorized access attack methodology does this activity represent?

A

Credential stuffing replaying public data breach dumps against a single administrative user

B

Password spraying testing a single common password across numerous accounts to evade per-account lockout policies

C

Dictionary brute-forcing attempting thousands of sequential passwords against an individual high-privilege account

D

Kerberoasting extracting service principal name tickets for offline cryptographic cracking

Test Your Knowledge

A penetration tester executes an Nmap Xmas scan (nmap -sX [target_ip]) against a legacy host. The scan reports that all 65,535 TCP ports are closed because the target host returned a TCP RST-ACK packet for every probed port, even though a concurrent TCP Connect scan confirmed that TCP ports 80, 443, and 445 are actively running open listening services. What architectural factor explains this scan result?

A

The target host is running a BSD-derived Unix kernel that silently drops malformed packets on closed ports

B

Stateful packet inspection firewalls automatically drop all packets carrying the URG flag regardless of destination

C

The target host operates an operating system stack (such as Microsoft Windows) that does not adhere strictly to RFC 793 and replies with RST packets for all unexpected flag combinations

D

The network switch enforced 802.1Q VLAN tagging that stripped the TCP flags during transit

Sections you finish are checked off in the contents.