Scanning

Hi there,
I need some advise on the following.
I have an ip 128 with host vagrant/vagrant
I have another Ip 100 and the password is student/student.
The sutdent and student is able to elevate to root privilege user.
What is the usual first step I should take to loosen the defenses of the host.
How can I make use of the host to scan other devices?