Apply Section 4 target identification and analysis techniques: network discovery using passive (DNS lookups + interrogation of databases + WHOIS + Shodan) + active (port scans + ping sweeps + ICMP + traceroute) + network port and service identification (TCP/UDP scanning + service version detection + banner grabbing) + vulnerability scanning (Nessus + OpenVAS + Qualys + Rapid7 + Tenable) + wireless scanning (rogue AP detection + signal strength mapping + war driving for authorised assessments).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.