Setelah melakukan ping scan dan live system terdeteksi, attacker akan berusaha mencari open ports dan systems.
Terdapat beberapa teknik untuk melakukan ports dan services discovery, berikut teknik scanning dibagi berdasarkan kategori protokol yang digunakan:
TCP Scanning
- Open TCP scanning methods
- TCP Connect/Full Open Scan
- Stealth TCP scanning methods
- Half-open scan
- Inverse TCP Flag scan
- Xmas Scan
- FIN Scan
- Null Scan
- Maimon Scan
- ACK Flag Probe Scan
- TTL-Based Scan
- Window Scan
- Third Party and Spoofed TCP Scanning Methods
- IDLE/IP ID Header Scan
UDP Scanning
- UDP Scanning
SCTP Scanning
- SCTP INIT Scanning
- SCTP Cookie/ECHO Scanning
SSDP Scanning
- SSDP and List Scanning
IPv6 Scanning
- IPv6 Scanning