Performance Optimization

Performance Optimization

Optimizing the performance of scanning and enumeration tools is crucial to efficiently conduct security assessments. Proper optimization reduces scan time, minimizes network impact, and can help evade detection. This guide focuses on best practices for performance optimization across common security tools.

Scan Performance Considerations

When planning and executing scans, consider these key factors:

  1. Production Impact: High-intensity scans can negatively affect production systems

  2. Network Load: Excessive packets may congest network infrastructure

  3. Detection Risk: Aggressive scanning increases the chance of triggering security controls

  4. Time Constraints: Assessment windows may be limited and require efficiency

  5. Target Resilience: Some targets may be unable to handle aggressive scanning

Nmap Performance Optimization

Nmap offers several parameters to control scan speed and resource usage:

RTT Timeouts

Round-Trip Time (RTT) affects how long Nmap waits for responses:

# Default scan
sudo nmap 10.129.2.0/24 -F

# Optimized RTT
sudo nmap 10.129.2.0/24 -F --initial-rtt-timeout 50ms --max-rtt-timeout 100ms

The optimized scan can be significantly faster (as seen in the example below), but may miss some hosts:

Retry Rates

Controlling packet retries can dramatically speed up scans:

Reducing retries sacrifices reliability for speed:

Packet Rates

Setting packet transmission rates is extremely effective for increasing scan speed:

Impact on performance:

In this case, both scans found the same number of open ports (23), making this an effective optimization.

Timing Templates

Nmap provides six timing templates to simplify scan optimization:

  • -T 0 / -T paranoid: Extremely slow, used for IDS evasion

  • -T 1 / -T sneaky: Slow, also for IDS evasion

  • -T 2 / -T polite: Slows down to consume less bandwidth

  • -T 3 / -T normal: Default timing

  • -T 4 / -T aggressive: Faster scan assuming reliable network

  • -T 5 / -T insane: Extremely fast scan assuming very high bandwidth

Example usage:

Results:

Optimizing Web Application Scanning Tools

Gobuster Performance

FFUF Performance

Resource Management for Multi-Tool Scanning

When running multiple tools simultaneously:

  1. CPU allocation: Use nice to set process priorities

  2. Memory management: Monitor with htop and adjust tool parameters accordingly

  3. Process scheduling: Use at or cron to schedule scans during off-peak hours

  4. Distributed scanning: Split large scans across multiple machines

Network Considerations

Bandwidth Management

Connection Management

Target-Specific Optimizations

Adapting to Target Response Times

For targets with slow response times:

For highly responsive targets:

Scan Phasing

Break scans into phases for better performance:

  1. Discovery phase: Quick scan to find live hosts

  2. Service phase: Targeted scan on discovered hosts

  3. Deep inspection phase: Focused scans on specific services

Balancing Stealth and Speed

Different scenarios require different performance profiles:

Fast Enumeration (Internal Testing)

Stealth Enumeration (External Testing)

Balanced Approach

Performance Testing Methodology

To find the optimal settings for a given environment:

  1. Start with conservative settings

  2. Run a baseline scan and record time and results

  3. Gradually increase performance parameters

  4. Compare results between runs

  5. Find the point where increased performance doesn't cause missing results

Best Practices Summary

  1. Test your settings: Ensure optimizations don't compromise necessary data

  2. Start conservatively: Begin with lower speeds and increase gradually

  3. Know your target: Adapt settings to the specific environment

  4. Monitor impact: Watch for signs of network or target system stress

  5. Document approach: Record successful optimization parameters for future use

  6. Layer your scans: Start broad and light, then focus on areas of interest

By carefully managing scan performance, you can achieve the optimal balance between speed, comprehensive results, and minimal impact on target systems.

Last updated