Skip to content

Nmap in Depth

Nmap is the network-scanning tool par excellence: it discovers hosts, ports, services, versions, operating systems, and, with its scripting engine (NSE), even vulnerabilities. Mastering its options is the difference between a scan that takes hours and is noisy, and one that’s fast, precise, and tailored to what you need. It’s the central tool of active recon (see Active Reconnaissance).

nmap [scan type] [options] [target]
nmap -sS -sV -p- -T4 -oA output 10.0.0.5

The internal flow: host discovery (is it alive?) → port scan (what’s open?) → service/version detection → NSE.

nmap -sn 10.0.0.0/24 # ping sweep (only discover live hosts, no port scan)
nmap -Pn 10.0.0.5 # skip discovery (assume alive; useful if ICMP is blocked)
nmap -PS22,80,443 10.0.0.0/24 # discover by SYN to specific ports

-Pn is key when the host doesn’t respond to ping but does have services.

-sS SYN scan (default as root): fast, "stealthy" (doesn't complete the handshake)
-sT TCP connect: no privileges (completes the connection, noisier)
-sU UDP scan: slow but necessary (DNS 53, SNMP 161, etc.)
-sA ACK scan: map firewall rules (filtered vs unfiltered)
-p- all 65535 TCP ports
-p 80,443,8080 specific ports
--top-ports 100 the 100 most common
-F fast (top 100)
-T0..-T5 timing: T0 paranoid (evasion) ... T5 insane (fast, noisy)
--min-rate 1000 minimum packets per second

Typical efficient flow: first -p- --min-rate to find open ports fast, then -sV -sC only on those ports.

-sV service versions (banner + probes)
-sV --version-intensity 9 more aggressive
-O OS detection
-A aggressive: -sV -O -sC --traceroute (all together, noisy)

NSE takes Nmap from “what’s there” to “what can I do with it”:

-sC default scripts (safe, informative)
--script=vuln look for known vulnerabilities
--script=smb-enum-shares,smb-os-discovery -p445 target
--script=http-enum,http-title -p80,443 target
--script=ftp-anon,ssh-auth-methods target
--script-help=<script> what a script does
# categories: safe, default, discovery, vuln, exploit, brute, auth
-oA base saves in all 3 formats (.nmap, .gnmap, .xml)
-oN / -oG / -oX normal / greppable / XML
-v / -vv verbosity --open show only open ports

The .gnmap is ideal for grepping out ports/hosts to feed other tools.

-T2 / -T1 slower = less detectable
-f fragment packets
-D RND:5 decoys to obfuscate the origin
--source-port 53 origin from a "trusted" port
--data-length 50 add random data

An IDS will spot a -T5 -A -p- instantly; a slow, fragmented scan slips by more (see Firewall and IDS Evasion).

Detection: a host connecting to many ports of many destinations in a short time (scan signature), SYN without completing the handshake, known NSE probes. Mitigation: IDS/IPS (Suricata/Snort with port-scan rules), rate-limiting, segmentation, and not exposing unnecessary services. A well-detected scan exposes the attacker before they exploit anything.

  • Discover live hosts (-sn) or assume them (-Pn)
  • Full TCP port scan (-p- with —min-rate)
  • Key UDP ports (-sU —top-ports)
  • Version and OS detection (-sV -O) on the open ones
  • NSE per service (smb, http, ftp…) and —script=vuln
  • Save in all 3 formats (-oA) for grep/report
  • Apply timing/evasion if stealth matters
  • Feed other tools with the results