Enumeration
Systematically listing what exists on a target: services, users, shares, and configurations.
Once a target is identified, enumeration builds the detail: which ports are open, what software and version answers, which accounts exist, which shares are readable.
It is the least glamorous and most productive phase. Most successful intrusions come from something thorough enumeration found rather than from a novel exploit.
Where this comes up
Enumeration sits inside our penetration testing work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.