Skip to content

Nmap

Network scanner for host discovery, port scanning, and service and OS detection.

When I Use It

  • Verifying what is actually exposed on a host or network segment, including from outside the firewall
  • Checking that firewall rule changes did what they were supposed to
  • Finding hosts and services missing from the asset inventory
  • Seeing what an attacker's scan would have found

Only scan what you are authorized to scan

Get written approval before scanning networks you do not own or manage, and let the network team know, since scans can trip IDS alerts and occasionally disrupt fragile devices.

Installation

Common Tasks

Option Example Description
-sS nmap -sS [target] SYN scan ("half-open"): sends SYN and does not complete the TCP handshake; default when run as root
-sT nmap -sT [target] TCP connect scan: completes the full handshake; default without root privileges
-sU nmap -sU [target] UDP scan
-sA nmap -sA [target] ACK scan: maps firewall rules (filtered vs unfiltered); does not identify open ports
-sn nmap -sn 192.168.1.0/24 Host discovery only (ping sweep), no port scan
-Pn nmap -Pn [target] Skip host discovery and treat the target as up
-p nmap -p 22,80,443 [target] / nmap -p- [target] Specific ports / all 65535 ports
-sV nmap -sV [target] Service and version detection on open ports
-O nmap -O [target] OS detection
-A nmap -A [target] OS detection, version detection, default scripts, and traceroute
-T0 to -T5 nmap -T4 [target] Timing template, slowest to fastest
-v nmap -v [target] Verbose output
-oA nmap -oA scan1 [target] Save output in normal, XML, and grepable formats

Reading the Output

State Meaning
open A service is accepting connections
closed The host responded, but nothing is listening
filtered No response or an ICMP error; a firewall is probably dropping the traffic
unfiltered Reachable, but Nmap cannot tell whether open or closed (ACK scans)

Recognizing Nmap in logs: many connection attempts from one source to many ports or hosts in a short time; SYN scans leave a pattern of SYN, SYN/ACK, then RST from the scanner; IDS signatures for port scans.

Resources