Nmap in Depth
Nmap is the network-scanning tool par excellence: it discovers hosts, ports, services, versions, operating systems, and, with its scripting engine (NSE), even vulnerabilities. Mastering its options is the difference between a scan that takes hours and is noisy, and one that’s fast, precise, and tailored to what you need. It’s the central tool of active recon (see Active Reconnaissance).
Anatomy of a scan
Section titled “Anatomy of a scan”nmap [scan type] [options] [target]nmap -sS -sV -p- -T4 -oA output 10.0.0.5The internal flow: host discovery (is it alive?) → port scan (what’s open?) → service/version detection → NSE.
Host discovery
Section titled “Host discovery”nmap -sn 10.0.0.0/24 # ping sweep (only discover live hosts, no port scan)nmap -Pn 10.0.0.5 # skip discovery (assume alive; useful if ICMP is blocked)nmap -PS22,80,443 10.0.0.0/24 # discover by SYN to specific ports-Pn is key when the host doesn’t respond to ping but does have services.
Port scan types
Section titled “Port scan types”-sS SYN scan (default as root): fast, "stealthy" (doesn't complete the handshake)-sT TCP connect: no privileges (completes the connection, noisier)-sU UDP scan: slow but necessary (DNS 53, SNMP 161, etc.)-sA ACK scan: map firewall rules (filtered vs unfiltered)Port selection and speed
Section titled “Port selection and speed”-p- all 65535 TCP ports-p 80,443,8080 specific ports--top-ports 100 the 100 most common-F fast (top 100)-T0..-T5 timing: T0 paranoid (evasion) ... T5 insane (fast, noisy)--min-rate 1000 minimum packets per secondTypical efficient flow: first -p- --min-rate to find open ports fast, then -sV -sC only on those ports.
Service, version, and OS detection
Section titled “Service, version, and OS detection”-sV service versions (banner + probes)-sV --version-intensity 9 more aggressive-O OS detection-A aggressive: -sV -O -sC --traceroute (all together, noisy)NSE: the scripting engine
Section titled “NSE: the scripting engine”NSE takes Nmap from “what’s there” to “what can I do with it”:
-sC default scripts (safe, informative)--script=vuln look for known vulnerabilities--script=smb-enum-shares,smb-os-discovery -p445 target--script=http-enum,http-title -p80,443 target--script=ftp-anon,ssh-auth-methods target--script-help=<script> what a script does# categories: safe, default, discovery, vuln, exploit, brute, authOutput and format
Section titled “Output and format”-oA base saves in all 3 formats (.nmap, .gnmap, .xml)-oN / -oG / -oX normal / greppable / XML-v / -vv verbosity --open show only open portsThe .gnmap is ideal for grepping out ports/hosts to feed other tools.
Evasion (when stealth matters)
Section titled “Evasion (when stealth matters)”-T2 / -T1 slower = less detectable-f fragment packets-D RND:5 decoys to obfuscate the origin--source-port 53 origin from a "trusted" port--data-length 50 add random dataAn IDS will spot a -T5 -A -p- instantly; a slow, fragmented scan slips by more (see Firewall and IDS Evasion).
For the defense
Section titled “For the defense”Detection: a host connecting to many ports of many destinations in a short time (scan signature), SYN without completing the handshake, known NSE probes. Mitigation: IDS/IPS (Suricata/Snort with port-scan rules), rate-limiting, segmentation, and not exposing unnecessary services. A well-detected scan exposes the attacker before they exploit anything.
Testing checklist
Section titled “Testing checklist”- Discover live hosts (-sn) or assume them (-Pn)
- Full TCP port scan (-p- with —min-rate)
- Key UDP ports (-sU —top-ports)
- Version and OS detection (-sV -O) on the open ones
- NSE per service (smb, http, ftp…) and —script=vuln
- Save in all 3 formats (-oA) for grep/report
- Apply timing/evasion if stealth matters
- Feed other tools with the results