What is service discovery?¶
Service discovery is how somebody finds out what network services or applications are available on another system.
That might reveal remote desktop, file sharing, a web application, a database or an administrative interface. Once a useful service appears, it may become the next target.
A port can tell you where to look next¶
Suppose network discovery identifies a server at 10.24.8.17.
A later query finds:
| Port | Likely service | Useful next question |
|---|---|---|
| 445 | SMB / Windows file sharing | Was a share later accessed? |
| 3389 | Remote Desktop | Was there a successful remote login? |
| 443 | HTTPS / web application | Which application answered and was it used? |
| 22 | SSH | Was an SSH session later created? |
The important point is not memorising port numbers. It is that the response may reveal a service that can then be followed into its own logs.
Look for the source, target and response¶
Useful evidence may come from several places:
- the process or tool that sent the query;
- firewall or network records showing the destination and port;
- the target service showing the request;
- authentication records;
- application logs; and
- any later process or session activity on the target.
A service banner or open port can explain why a machine became interesting. It does not prove that access succeeded.
Follow the service into later records¶
If Remote Desktop appears on a server, look for later RDP authentication and session activity.
If file sharing appears, look for share access and file events.
If a web application responds, identify the application and check its access and authentication logs.
This is why service discovery is useful: it gives you a route into a more specific set of records.
Normal tools may do the same thing¶
Vulnerability scanners, inventory systems and administrators all check services.
Compare the source, timing, target range and what follows.
A scheduled vulnerability scan across every server is one thing. A new process on a compromised workstation finding RDP on one server and then immediately trying to log in is another.
Could legitimate administration look like reconnaissance? deals with that comparison directly.
The practical point is: service discovery tells you what appeared to be available. The next job is to see whether anybody actually used it.