Once you know that your target exists, you can use nmap to find out (fingerprint) what type and version of the operating system is running on your target system. You can then use a packet sniffer to listen on an ethernet port for things like passw...