Recon
OS Fingerprinting
OS fingerprinting techniques: TTL analysis, Nmap detection, p0f passive fingerprinting, and banner grabbing.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
OS fingerprinting techniques: TTL analysis, Nmap detection, p0f passive fingerprinting, and banner grabbing.
nmap -O TARGET
nmap -O --osscan-guess TARGET
nmap -A TARGET # OS + version + scripts
| OS | Default TTL |
|---|---|
| Linux | 64 |
| Windows | 128 |
| Cisco/Network | 255 |
| Solaris | 255 |
ping -c 1 TARGET | grep ttl
p0f -i eth0
p0f -i eth0 -o output.txt
p0f -r capture.pcap
nc -nv TARGET 22
nmap -sV -p 22 TARGET
curl -I http://TARGET
telnet TARGET 80
HEAD / HTTP/1.1
Host: TARGET
nmap --script=smb-os-discovery TARGET
nmap -p 445 --script=smb-os-discovery TARGET
| Method | Command |
|---|---|
| Active OS | nmap -O TARGET |
| TTL check | ping -c 1 TARGET |
| Passive | p0f -i eth0 |
| Banner grab | nc -nv TARGET PORT |
| SMB OS | nmap --script=smb-os-discovery TARGET |