← All cheat sheets

MASSCAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Nmap Command Builder

OVERVIEW#

Masscan is the fastest Internet port scanner. It can scan the entire
Internet in under 6 minutes, transmitting 10 million packets/sec.
Uses asynchronous transmission for extreme speed.

BASIC USAGE#

masscan <target> -p <ports>      # Basic scan
masscan <target> -p80,443        # Scan specific ports
masscan <target> -p1-65535       # Scan all ports

TARGET SPECIFICATION#

masscan 192.168.1.0/24 -p80     # Scan subnet
masscan 10.0.0.0/8 -p80         # Scan /8 network
masscan 192.168.1.1 -p1-1024    # Scan single host
masscan -iL targets.txt -p80    # Read targets from file
masscan 192.168.1.0/24 --excludefile exclude.txt -p80
                                 # Exclude hosts from file

PORT SPECIFICATION#

masscan <target> -p80            # Single port
masscan <target> -p80,443        # Multiple ports
masscan <target> -p80-100        # Port range
masscan <target> -p0-65535       # All ports
masscan <target> -pU:53          # UDP port
masscan <target> -pU:53,T:80    # Mixed TCP/UDP
masscan <target> --top-ports 100 # Top 100 ports

RATE CONTROL#

masscan <target> -p80 --rate 1000
                                 # 1000 packets/sec
masscan <target> -p80 --rate 10000
                                 # 10000 packets/sec
masscan <target> -p80 --rate 100000
                                 # 100000 packets/sec (be careful!)
masscan <target> -p80 --max-rate 1000000
                                 # Max rate limit
masscan <target> -p80 --banners  # Grab service banners
masscan <target> -p80 --banners --source-port 61000
                                 # Banner grab with source port

OUTPUT OPTIONS#

masscan <target> -p80 -oL out.txt    # List format (default)
masscan <target> -p80 -oX out.xml    # XML format
masscan <target> -p80 -oG out.gnmap  # Greppable format
masscan <target> -p80 -oJ out.json   # JSON format
masscan <target> -p80 -oB out.bin    # Binary format

NETWORK OPTIONS#

masscan <target> -p80 --adapter-ip 192.168.1.100
                                 # Set source IP
masscan <target> -p80 --adapter-port 61000
                                 # Set source port
masscan <target> -p80 --adapter-mac 00:11:22:33:44:55
                                 # Set source MAC
masscan <target> -p80 -e eth0    # Set network interface
masscan <target> -p80 --router-mac 00:11:22:33:44:55
                                 # Set gateway MAC

TIMING & RETRY#

masscan <target> -p80 --retries 2
                                 # Number of retries (default: 0)
masscan <target> -p80 --wait 5   # Seconds to wait for replies
masscan <target> -p80 --ttl 255  # Set TTL value

RESUME & CONFIG#

masscan --resume paused.conf     # Resume interrupted scan
masscan -c masscan.conf          # Load config file
masscan <target> -p80 --echo > config.conf
                                 # Save current config

EXAMPLES#

# Quick scan of common web ports on a /24
masscan 192.168.1.0/24 -p80,443,8080,8443 --rate 1000

# Full port scan of single host
masscan 192.168.1.1 -p0-65535 --rate 1000

# Scan with banner grabbing
masscan 10.0.0.0/24 -p21,22,80,443 --banners --rate 500

# Large-scale scan with output
masscan 10.0.0.0/8 -p80 --rate 100000 -oJ results.json

# Scan top ports with exclude list
masscan 192.168.0.0/16 --top-ports 100 --excludefile exclude.txt --rate 10000

# UDP scan for DNS
masscan 10.0.0.0/24 -pU:53 --rate 500

NMAP COMPATIBILITY#

# Masscan uses similar syntax to nmap where possible
# Key differences:
# - No service detection (-sV equivalent uses --banners)
# - No OS detection
# - No scripting engine
# - Uses --rate instead of -T timing
# - Default is SYN scan only

NOTES#

- Requires root privileges
- Uses custom TCP/IP stack (bypasses OS stack)
- Can overwhelm networks - use appropriate --rate
- Does NOT use OS network stack (no iptables needed)
- Add iptables rule to prevent RST interference:
  iptables -A INPUT -p tcp --dport 61000 -j DROP
- Binary output can be converted: masscan --readscan out.bin -oX out.xml
- Pair with nmap for detailed service/version scanning