Research session unavailable. No participant research session is associated with this browser. Use the participant access link supplied by the facilitator.
← Back to dashboard
TA0043 Reconnaissance · T1595.002 · Vulnerability Scanning

Identify service versions

Completed
Lesson Purpose

What you are learning

Use lightweight Nmap service detection on the same small fixed port set to gather software and version clues.

Learning Objectives
Why This Matters

Knowing that a port is open provides only limited context. Identifying the software behind that port gives defenders more actionable information for vulnerability management, patch prioritization, exposure reviews, and monitoring. Accurate service identification also helps reduce false assumptions about what is actually running.

Exercise

Follow the exercise instructions provided by the trainer for this lesson.

Controlled Tool Runner

Authorized reconnaissance action

Commands, flags, ports, and targets are fixed by the trainer. The participant cannot enter arbitrary shell commands.

Run service identification

Identify services only on TCP ports 22 and 80 on the facilitator-authorized target.

Findings

Enter one finding per line. Identity and condition are locked by the facilitator.

Learning Moment

Version strings help form patching and exposure hypotheses, but banners may be missing, proxied, stale, or intentionally misleading.

Defender Perspective

Service-detection probes can create distinctive connection patterns and application errors visible in IDS, firewall, reverse-proxy, and host logs.