Enumeration: How to Map Services and Users in a Lab Environment

Enumeration in penetration testing must only be performed within an approved Scope and Rules of Engagement. The process includes information gathering, controlled verification, evidence, risk assessment, remediation, and retest.
Professional penetration testing is an authorized and defined process, not a collection of commands. Scope, Rules of Engagement, evidence, risk assessment, remediation, and retest are an integral part of the work. This article focuses on enumeration in penetration testing and is intended for PT students. The goal is to provide a working methodology that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. Services, versions, and users can indicate a direction, but their significance depends on time, asset, user, and expected activity. Therefore, we will build the test around an investigative question, required evidence, and a clear criterion for completion.
The practical scenario in the article is: enumeration of two authorized lab machines. All examples are lab data or descriptions of processes. When dealing with Penetration Testing, Web, or Cloud, one must only work with explicit authorization, a defined scope, and the ability to stop the test.




