What is network discovery?¶
Network discovery is how somebody learns what other systems are around them and which of those systems appear to be reachable.
On an internal network, that might mean looking for other IP addresses, hostnames, open services or routes. The useful investigative question is not simply “was there a scan?” It is what was being looked for, what answered, and what happened to those targets afterwards.
What might it look like?¶
Imagine a compromised workstation at 10.24.8.12 starts checking nearby addresses.
A simplified network record might show:
10.24.8.12 destination=10.24.8.17 port=445 result=allowed10:15:13Z source=10.24.8.12 destination=10.24.8.21 port=445 result=blocked10:15:14Z source=10.24.8.12 destination=10.24.8.17 port=3389 result=allowedThat immediately gives you useful targets to follow.
The source system appears interested in 10.24.8.17. If the same address later appears in authentication, remote-service or endpoint records, the discovery activity may help explain how that system was selected.
Where can the evidence sit?¶
Different systems may record different parts of the search:
| Source | What it can tell you |
|---|---|
| Endpoint / EDR | Which process or command initiated the activity |
| Firewall | Which destinations and ports were contacted |
| DNS / name-resolution records | Which hostnames were looked up |
| Target server | Whether the connection reached it and what it did next |
| Remote-access logs | Whether the source workstation was itself being controlled remotely |
The source machine tells you what started the activity. The network tells you where it went. The target tells you what actually arrived.
Discovery is not the same as access¶
This distinction matters.
A scan may show that a host or service was found. It does not automatically show that somebody logged in, exploited it or ran anything there.
So if 10.24.8.17 responded, follow that address into:
- authentication logs;
- remote-service logs;
- endpoint activity on the target; and
- any later file or process records.
That is how you move from “this system was discovered” to “this system was actually used”.
Does reconnaissance prove the next stage of an attack occurred? takes that next step in more detail.
Compare it with normal network activity¶
Administrators, monitoring platforms and vulnerability scanners may do very similar things.
If the organisation runs a scheduled scanner every night, a sweep across dozens of addresses at 02:00 may be completely expected. The same pattern from an employee laptop immediately after an unusual login may deserve much more attention.
Could legitimate administration look like reconnaissance? is the useful comparison when the behaviour itself is dual-use.
The practical point is: network discovery gives you a map of what the source looked for and what answered. Use those returned systems and services as pivots into the next records.