Summary
In this chapter, we looked at the networking and enumeration tools netdiscover and nmap and learned how to scan networks for open hosts and view details such as IPs, MAC addresses, and hostnames and went a bit further with Nmap to further discover more host details, such as open ports, running services and their versions, computer names, and domains. We then moved on to finding IoT devices using Shodan.io and used various search filters to find firewalls, servers, and CCTV cameras.
These tools can be very useful to anyone gathering information on local and remote devices that may be part of a network DFIR investigation.
Next up, we’ll look at a Network Forensics Analysis Tool (NFAT) called Xplico. See you in the next chapter.