Back to Cybersecurity

Network Reconnaissance & Vulnerability Assessment

Vulnerability AssessmentAugust 2026

Environment & Objective

Target Environment: CyberShujaa Practical Lab Network

Identify open ports, running services, and misconfigurations on a simulated target environment.

Tools & Instrumentation

NmapWiresharkOpenVASMetasploit

Analysis & Execution Strategy

Executed SYN stealth scans to map network topology. Discovered unpatched service versions and insecure cleartext protocol usage.

Security Findings & Evidence

Identified outdated service ports vulnerable to remote code execution and unencrypted credentials on HTTP endpoints.

Evidence:

Scan logs, packet capture files (.pcap), and structured risk assessment report.

Remediation & Recommendation

Enforce TLS 1.3 encryption across all internal services, restrict unused ports with firewall rules, and apply security patches.

Key Practical Lessons Learned

Automated vulnerability scanners produce false positives — manual verification with Nmap and manual inspection is essential.

CyberShujaa Practical Lab Series