🛠️Hosts discovery
Theory
Practice
ARP discovery
# (active) scan all private ranges (i.e. 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8)
netdiscover -i $INTERFACE
# (active) scan a given range (e.g. 192.168.0.0/24)
netdiscover -i $INTERFACE -r $RANGE
# passive scan (doesn't send packets)
netdiscover -i $INTERFACE -p
# (active) scan a given range
nmap -sn $RANGENBT discovery
DNS queries
DNSICMP discovery
ICMPv6 discovery
Resources
Last updated
Was this helpful?