Skip to content

nmap

nmap (Network Mapper) is the standard network and port scanner. It discovers hosts, open ports, services, versions and, with its scripts (NSE), detects vulnerabilities and enumerates services. It’s almost always the first step of any pentest or CTF (see recon, CTF methodology).

nmap -sS -p- 10.10.10.10 # SYN scan of ALL ports (fast, needs root)
nmap -sV -sC -p 22,80,443 host # service version + default scripts
nmap -sn 10.10.10.0/24 # host discovery (ping sweep) without scanning ports
nmap -Pn host # skip the ping (host not responding to ICMP)
# 1. discover ALL open ports, fast
nmap -sS -p- --min-rate 5000 -oN allports.txt 10.10.10.10
# 2. enumerate thoroughly ONLY the open ports found
nmap -sV -sC -p 22,80,445 -oN detail.txt 10.10.10.10
# -> don't scan -sC -sV over all 65535 ports (slow); discover first, then go deep
-sS/-sT SYN scan (stealthy, root) / TCP connect (no root)
-sU UDP scan (slow but important: DNS, SNMP, etc.)
-p- all ports (1-65535); -p 80,443 specific ports; --top-ports N
-sV version detection; -O OS detection
-sC default scripts (safe); --script=... specific scripts
-T4 faster timing (T0 stealthy ... T5 aggressive)
-oA base save in all 3 formats (normal/grepable/XML)
nmap --script vuln host # vuln-detection scripts
nmap --script smb-enum-shares host # enumerate SMB shares (see Windows & AD area)
nmap --script ssl-enum-ciphers -p443 host # audit TLS (see crypto-tls)
nmap --script http-enum host # enumerate common web paths
# scripts in /usr/share/nmap/scripts/ organized by category
- --min-rate speeds up; -T4/-T5 aggressive (noisy); -T1/-T2 slow and stealthy
- on fragile/OT networks: do NOT scan aggressively (see ot-protocolos) -> can crash services
- fragmentation (-f), decoys (-D), source port to evade controls (carefully)
  • Two-phase flow: discover all ports fast, then -sV -sC only on the open ones.
  • NSE turns nmap into an enumerator and vuln detector (SMB, TLS, http-enum).
  • Always save the output (-oA) to document and for the report.
  • Mind stealth/fragility: in OT/prod, aggressive scanning can cause crashes (Industrial protocols (Modbus)).
  • Two phases: fast port discovery (-p- --min-rate) then -sCV only on open ports; don’t brute-force -sCV -p-.
  • Common mistake: scanning as non-root and losing SYN scan/OS detection; use sudo for -sS/-O.
  • Tune timing (-T4 on good networks, lower on fragile ones) and always save output (-oA).
  • NSE categories (--script vuln, safe, default) are powerful but some are intrusive; know what you’re firing.
  • Host discovery of the range (or -Pn if no ping response)
  • Scan ALL ports (fast, -p-)
  • Enumeration -sV -sC only on open ports
  • UDP on key services (DNS/SNMP) if applicable
  • NSE for vulns/enumeration (SMB, TLS, http)
  • Save output (-oA) for the report
  • Adjust timing/stealth to the environment (careful in OT/prod)