Back to all posts
Day 68Thursday, April 9, 20262 min read

Testing Network Connectivity and Verifying Open Ports

cybersecuritynetworkinglinuxlearningprocess
View original post

πŸ”„ Topic

Testing connectivity between systems and verifying whether services are reachable over the network.


🎯 Goal

Understand how to verify whether a remote service is accessible and correctly listening on a port.


πŸ›  What I Did

Used tools like:

  • Test-NetConnection (Windows)
  • netcat (nc)
  • ss -tulpn (Linux)

to check:

  • whether port 22 was reachable
  • whether services were listening

πŸ”— Key Cybersecurity Connections

Port connectivity testing is essential for:

  • troubleshooting infrastructure
  • validating service availability
  • detecting exposed services

Attackers use the same techniques during:

  • reconnaissance
  • network scanning
  • lateral movement

πŸ” Investigation Questions

  • Is the target port open?
  • Is a service actually listening?
  • Is the issue network-level or host-level?

🚨 Detection Opportunities

  • port scanning activity (multiple connection attempts)
  • unusual probing across multiple hosts
  • repeated connection failures

🧭 MITRE ATT&CK Techniques

  • T1046 β€” Network Service Discovery

⚠ Challenges

Distinguishing between:

  • network reachability
  • service availability

A host can be reachable but still not accept connections.


πŸ“š What I Learned

  • open port β‰  reachable service
  • tools must be used together for validation
  • connectivity issues must be broken down step by step

➑ Next Steps

  • simulate port scanning scenarios
  • analyze logs generated by connection attempts

🧠 Reflection

This reinforced a key principle:

Always test assumptions at the network level.


🧩 Lessons Learned

What worked

Using multiple tools to verify connectivity.

What broke

Assuming reachability meant service availability.

Why it broke

Incomplete understanding of networking layers.

Fix / takeaway

Validate each layer independently.


πŸ“ˆ Skill Progression Context

This builds core networking and investigation skills used daily in SOC environments.


πŸ˜„ TL;DR

Just because you can ping it…
doesn’t mean you can talk to it.