Skip to content
← LibraryTechnique entry
N-NMAP-INTERNALDiscovery

Internal Nmap Sweep

Authenticated / unauthenticated TCP+UDP sweep against discovered subnets — finds web admin panels, MSSQL, exposed prints.

§ Where this technique fits

N-NMAP-INTERNAL is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 20 approved dossiers in the registry, typically at step 2.1 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Account Discovery
    T1087 · Discovery
    seen 3×
  2. 02
    Default Credentials
    W-AUTH-DEFAULT · Credential Access
    seen 3×
  3. 03
    ADB Open on Network
    MOB-ADB-OPEN · Initial Access
    seen 1×
  4. 04
    DICOM C-STORE Unauth Access
    HC-DICOM-CSTORE · Collection
    seen 1×
  5. 05
    EternalBlue (MS17-010 / CVE-2017-0144)
    CVE-ETERNALBLUE · Initial Access
    seen 1×
  6. 06
    HMI Default Credentials
    OT-HMI-DEFAULTS · Initial Access
    seen 1×
  7. 07
    Industroyer2 Timed IEC-104 Sweep
    ICS-INDUSTROYER2 · Impact
    seen 1×
  8. 08
    LLMNR/NBT-NS Poisoning and SMB Relay
    T1557.001 · Credential Access
    seen 1×