Enumeración de puertos

Escanear TCP

Escanear UDP

Enumeración DNS

https://book.hacktricks.xyz/network-services-pentesting/pentesting-dns

Enumeración WEB

https://www.wappalyzer.com/

feroxbuster -u http://'<IP>'/ -x html,php -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
ffuf -c -w /usr/share/wfuzz/wordlist/general/megabeast.txt -u http://'<IP>'/FUZZ  

ffuf -c -w /usr/share/seclists/Discovery/DNS/n0kovo_subdomains.txt -u <http://fqdn.com/> -H "Host: FUZZ.fqdn.com" -fw 6
#To apis
/users/v1
/v2
...

SMB

https://book.hacktricks.xyz/network-services-pentesting/pentesting-smb

nmap -v -p 139,445 --script smb-os-discovery '<IP>'
enum4linux -a '<IP>'
smbclient -L '<IP>'
smbclient -L '<IP>' -U '%'
smbclient -L '<IP>' -U 'user'
net view \\\\'<IP>' /all

SMTP

https://book.hacktricks.xyz/network-services-pentesting/pentesting-smtp