2.1 Understanding your engagement scope2.1.1 Black-box, white-box, and grey-box scoping2.1.2 Capsulecorp2.1.3 Setting up the Capsulecorp Pentest environment2.2 Internet Control Message Protocol2.2.1 Using the ping command2.2.2 Using bash to pingsweep a network range2.2.3 Limitations of using the ping command2.3 Discovering hosts with Nmap2.3.1 Primary output formats2.3.2 Using remote management interface ports2.3.3 Increasing Nmap scan performance2.4 Additional host-discovery methods2.4.1 DNS brute-forcing2.4.2 Packet capture and analysis2.4.3 Hunting for subnetsSummary