nmap

  • network scanner

usage

find targets for smb relay

$ nmap --script=smb2-security-mode.nse -p445 192.168.122.0/24 [-Pn]
  • NTLM signing: searching for enabled but not required

using vulners script

$ nmap -sV --script vulners <target>

standard options

  • -p-: for all ports
  • -T3: don’t become very slow