Mapping is best done with nessus, firewalk, ping, traceroute, and the route servers for network and transport layer. tcpdump, arp and anti-sniff for ethernet/link layer. Nmap is fine for session. Application, well, that's brute forcers, skriptz, whisker, and good old fashioned kung-f00 with some genuine clue thrown in for good measure. - batz (batsy[at]VAPOUR.NET)

