network-discovery

v2026.09.24

Network host and port discovery with nmap. Use when scanning TCP ports, enumerating hosts on a subnet, or identifying running services and versions.

GitHub
Install command
npx skhub add laurigates/network-discovery
Markdown
SKILL.md

Network Discovery

When to Use This Skill

ScenarioUse this skillAlternative
Scan all 65,535 TCP ports on a target quicklyYes (RustScan)
Enumerate live hosts on a subnetYes (arp-scan-rs)
Identify running services and versions on open portsYes (nmap -sV)
Run NSE vulnerability or enumeration scriptsYes (nmap --script)
Detect OS fingerprint of a remote hostYes (nmap -O)
Discover which switch port a server is on (LLDP)layer2-discovery (lldpcli)
Trace the route or diagnose latency to a hostnetwork-diagnostics (trippy, gping)
Resolve DNS records for a domaindns-tools (dog, dig)
Stress test an HTTP endpoint under loadhttp-load-testing (oha)
Monitor which process is using bandwidthnetwork-monitoring (bandwhich)
Inspect or configure the host's own IPs, links, or routesinterface-state (ip)

Core Expertise

Network discovery follows a two-phase approach: fast enumeration followed by deep analysis.

Why This Workflow

PhaseToolPurposeTime
DiscoveryRustScanScan all 65,535 TCP portsSeconds
Discoveryarp-scan-rsFind hosts on local networkSub-second
AnalysisnmapService detection, scriptsMinutes

RustScan Advantages

  • Scans all ports in 3-8 seconds (vs nmap's minutes/hours)
  • Automatically chains into nmap for service detection
  • Handles ulimit and batch sizing for reliability
  • Written in Rust for memory safety and speed

arp-scan-rs Advantages

  • Faster than traditional arp-scan
  • Built-in scan profiles (default, fast, stealth)
  • VLAN tagging support
  • JSON output for parsing

Essential Commands

RustScan - Fast Port Discovery

# Scan single host (all 65k ports)
rustscan -a 192.168.1.100

# Scan with nmap service detection
rustscan -a 192.168.1.100 -- -sV

# Scan with nmap scripts (default safe scripts)
rustscan -a 192.168.1.100 -- -sV -sC

# Scan multiple hosts
rustscan -a 192.168.1.100,192.168.1.101

# Scan from file
rustscan -a hosts.txt

# Scan specific ports only
rustscan -a 192.168.1.100 -p 22,80,443

# Scan port range
rustscan -a 192.168.1.100 -r 1-1000

# Adjust for reliability (slower but more accurate)
rustscan -a 192.168.1.100 --ulimit 5000 --batch-size 2500

arp-scan-rs - Local Network Discovery

# Scan local network (auto-detect interface)
arp-scan-rs -l

# Scan specific interface
arp-scan-rs -i en0

# Scan specific range
arp-scan-rs 192.168.1.0/24

# Fast profile (less accurate, faster)
arp-scan-rs -l --profile fast

# Stealth profile (slower, harder to detect)
arp-scan-rs -l --profile stealth

# JSON output for parsing
arp-scan-rs -l --format json

# With VLAN tagging
arp-scan-rs -l --vlan 100

# Resolve hostnames
arp-scan-rs -l --resolve

nmap - Deep Service Analysis

Use nmap after RustScan identifies open ports:

# Service version detection
nmap -sV -p 22,80,443 192.168.1.100

# Service + default scripts
nmap -sV -sC -p 22,80,443 192.168.1.100

# OS fingerprinting (requires root)
sudo nmap -O -p 22,80,443 192.168.1.100

# Aggressive scan (version, scripts, OS, traceroute)
sudo nmap -A -p 22,80,443 192.168.1.100

# Vulnerability scripts
nmap --script vuln -p 80,443 192.168.1.100

# Specific service scripts
nmap --script http-* -p 80,443 192.168.1.100

# UDP scan (slower, requires root)
sudo nmap -sU -p 53,161 192.168.1.100

Common Patterns

Full Network Reconnaissance

# 1. Discover live hosts
arp-scan-rs -l --format json > hosts.json

# 2. Extract IPs and scan ports
arp-scan-rs -l | awk '{print $1}' > hosts.txt
rustscan -a hosts.txt -- -sV -oN scan-results.txt

# 3. Deep dive on specific services
nmap -sV -sC --script vuln -p 22 -iL hosts.txt

Quick Web Server Discovery

# Find hosts with web servers
rustscan -a 192.168.1.0/24 -p 80,443,8080,8443 -- -sV

# Enumerate web technologies
nmap --script http-headers,http-title -p 80,443 192.168.1.100

Quiet/Stealth Scanning

# Slow ARP discovery
arp-scan-rs -l --profile stealth

# RustScan with lower batch (less noisy)
rustscan -a 192.168.1.100 --batch-size 500 --ulimit 1000

# nmap timing template (T0=paranoid, T1=sneaky)
nmap -T1 -sV -p 22,80 192.168.1.100

Service-Specific Deep Dives

# SSH enumeration
nmap --script ssh-* -p 22 192.168.1.100

# SMB enumeration
nmap --script smb-* -p 445 192.168.1.100

# DNS enumeration
nmap --script dns-* -p 53 192.168.1.100

Agentic Optimizations

ContextCommand
Quick port checkrustscan -a $IP -p $PORTS 2>/dev/null
Host discoveryarp-scan-rs -l --format json 2>/dev/null
Minimal outputrustscan -a $IP --greppable
JSON parsingarp-scan-rs -l --format json | jq -r '.[].ip'
Service IDs onlynmap -sV -p $PORTS $IP -oG - | grep open
Suppress bannersrustscan -a $IP -q -- -sV
Fast local scanarp-scan-rs -l --profile fast --format json

Quick Reference

RustScan Flags

FlagDescription
-aTarget address(es) or file
-pSpecific ports (comma-separated)
-rPort range (e.g., 1-1000)
--ulimitMax file descriptors (default: 5000)
--batch-sizePorts per batch (default: 4500)
--timeoutTimeout in ms (default: 1500)
-g, --greppableGreppable output format
-qQuiet mode
--Pass remaining args to nmap

arp-scan-rs Flags

FlagDescription
-lScan local network
-iInterface to use
--profileScan profile (default/fast/stealth)
--formatOutput format (plain/json)
--vlanVLAN ID for tagging
--resolveResolve hostnames
--timeoutResponse timeout in ms

nmap Common Flags

FlagDescription
-sVService version detection
-sCDefault script scan
-OOS detection (requires root)
-AAggressive (version + scripts + OS)
-pPort specification
-T<0-5>Timing template (0=slowest)
-oNNormal output to file
-oGGreppable output
-oXXML output
--scriptRun specific NSE scripts
-iLInput from host list file

nmap Timing Templates

TemplateNameUse Case
-T0ParanoidIDS evasion
-T1SneakyIDS evasion
-T2PoliteLess bandwidth
-T3NormalDefault
-T4AggressiveFast networks
-T5InsaneVery fast networks

Error Handling

RustScan Issues

"Too many open files":

# Reduce ulimit and batch size
rustscan -a $IP --ulimit 2000 --batch-size 1000

Slow scans:

# Increase batch size (if system allows)
rustscan -a $IP --batch-size 8000 --ulimit 10000

arp-scan-rs Issues

"Permission denied":

# ARP scanning requires raw socket access
sudo arp-scan-rs -l

No hosts found:

# Verify interface
arp-scan-rs -l -i en0  # Specify correct interface

nmap Issues

"requires root":

# OS detection and some scans need root
sudo nmap -O -p 22 $IP

Slow service detection:

# Limit version intensity
nmap -sV --version-intensity 2 -p $PORTS $IP
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

networking-plugin/skills/network-discovery

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3