NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
Target Identification

NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) 3: Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning

Apply Section 4 target identification and analysis techniques: network discovery using passive (DNS lookups + interrogation of databases + WHOIS + Shodan) + active (port scans + ping sweeps + ICMP + traceroute) + network port and service identification (TCP/UDP scanning + service version detection + banner grabbing) + vulnerability scanning (Nessus + OpenVAS + Qualys + Rapid7 + Tenable) + wireless scanning (rogue AP detection + signal strength mapping + war driving for authorised assessments).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.