# Scan for live hosts in the networkfping-g<subnet>|grep-v"unreachable"|awk'{print $1}'nmap-sn-vv<subnet>-oNlive_hosts# Scan top 100 ports with slow speed to avoid issues in tunnelnmap-F-iLlive_hosts-T2-vv-Pn-oNnmap_scan
Enumerate common services.
Start with trying to read SMB or NFS shares.
Spend time on HTTP websites if available, potentially get foothold on the host.
Found new creds???
Enumerate shares again.
Check the password on the users you dont know the password of.