4. ENUMERATION
“Enumeration can best be defined as the process of counting. From a security standpoint, it’s the process the attacker follows before an attack. The attacker is attempting to count or identify systems and understand their role or purpose.
This may mean the identification of open ports, applications, vulnerable services, DNS or NetBIOS names, and IP addresses before an attack.”
Michael Gregg (2008, p 149)
This means at this stage it’s only a matter of time before the attacker compromises a system on the network.
The main aim of this stage is to find:
-
User accounts for password guessing.
-
system groups and roles