nmap
nmap (Network Mapper) is the standard network and port scanner. It discovers hosts, open ports, services, versions and, with its scripts (NSE), detects vulnerabilities and enumerates services. It’s almost always the first step of any pentest or CTF (see recon, CTF methodology).
Basic scans
Section titled “Basic scans”nmap -sS -p- 10.10.10.10 # SYN scan of ALL ports (fast, needs root)nmap -sV -sC -p 22,80,443 host # service version + default scriptsnmap -sn 10.10.10.0/24 # host discovery (ping sweep) without scanning portsnmap -Pn host # skip the ping (host not responding to ICMP)Typical flow (two phases)
Section titled “Typical flow (two phases)”# 1. discover ALL open ports, fastnmap -sS -p- --min-rate 5000 -oN allports.txt 10.10.10.10# 2. enumerate thoroughly ONLY the open ports foundnmap -sV -sC -p 22,80,445 -oN detail.txt 10.10.10.10# -> don't scan -sC -sV over all 65535 ports (slow); discover first, then go deepKey options
Section titled “Key options”-sS/-sT SYN scan (stealthy, root) / TCP connect (no root)-sU UDP scan (slow but important: DNS, SNMP, etc.)-p- all ports (1-65535); -p 80,443 specific ports; --top-ports N-sV version detection; -O OS detection-sC default scripts (safe); --script=... specific scripts-T4 faster timing (T0 stealthy ... T5 aggressive)-oA base save in all 3 formats (normal/grepable/XML)NSE (Nmap Scripting Engine)
Section titled “NSE (Nmap Scripting Engine)”nmap --script vuln host # vuln-detection scriptsnmap --script smb-enum-shares host # enumerate SMB shares (see Windows & AD area)nmap --script ssl-enum-ciphers -p443 host # audit TLS (see crypto-tls)nmap --script http-enum host # enumerate common web paths# scripts in /usr/share/nmap/scripts/ organized by categoryPerformance and stealth
Section titled “Performance and stealth”- --min-rate speeds up; -T4/-T5 aggressive (noisy); -T1/-T2 slow and stealthy- on fragile/OT networks: do NOT scan aggressively (see ot-protocolos) -> can crash services- fragmentation (-f), decoys (-D), source port to evade controls (carefully)Blue Team / use
Section titled “Blue Team / use”- Two-phase flow: discover all ports fast, then
-sV -sConly on the open ones. - NSE turns nmap into an enumerator and vuln detector (SMB, TLS, http-enum).
- Always save the output (
-oA) to document and for the report. - Mind stealth/fragility: in OT/prod, aggressive scanning can cause crashes (Industrial protocols (Modbus)).
Tips and gotchas
Section titled “Tips and gotchas”- Two phases: fast port discovery (
-p- --min-rate) then-sCVonly on open ports; don’t brute-force-sCV -p-. - Common mistake: scanning as non-root and losing SYN scan/OS detection; use sudo for
-sS/-O. - Tune timing (
-T4on good networks, lower on fragile ones) and always save output (-oA). - NSE categories (
--script vuln,safe,default) are powerful but some are intrusive; know what you’re firing.
Testing checklist
Section titled “Testing checklist”- Host discovery of the range (or -Pn if no ping response)
- Scan ALL ports (fast, -p-)
- Enumeration -sV -sC only on open ports
- UDP on key services (DNS/SNMP) if applicable
- NSE for vulns/enumeration (SMB, TLS, http)
- Save output (-oA) for the report
- Adjust timing/stealth to the environment (careful in OT/prod)