NAABU
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Nmap Command Builder
OVERVIEW#
Naabu (ProjectDiscovery) is a fast SYN/CONNECT port scanner focused on reliability and pipeline integration. It pairs with subfinder/httpx and can hand off discovered ports to nmap for service detection. Authorized scope only.
BASIC USAGE#
naabu -host corp.lu # Scan a host (top ports) naabu -host 192.0.2.10 # Scan an IP naabu -list hosts.txt # Hosts from a file subfinder -d corp.lu -silent | naabu # From a pipe naabu -host corp.lu -silent # Clean output for pipes
PORT SELECTION#
naabu -host corp.lu -p 80,443,8080 # Specific ports naabu -host corp.lu -p - # All 65535 ports naabu -host corp.lu -top-ports 100 # Top 100 ports naabu -host corp.lu -top-ports 1000 # Top 1000 naabu -host corp.lu -ep 80,443 # Exclude ports naabu -host corp.lu -pf portlist.txt # Ports from file
SCAN TYPE & PERFORMANCE#
naabu -host corp.lu -s s # SYN scan (needs root) naabu -host corp.lu -s c # CONNECT scan naabu -host corp.lu -rate 2000 # Packets/sec naabu -host corp.lu -c 50 # Concurrency naabu -host corp.lu -retries 2 -timeout 1000 # Reliability tuning naabu -host corp.lu -warm-up-time 2
HOST DISCOVERY / PROBES#
naabu -host corp.lu -sn # Ping/host discovery only naabu -host corp.lu -Pn # Skip host discovery naabu -host corp.lu -exclude-cdn # Skip CDN full-port scans
NMAP HANDOFF#
naabu -host corp.lu -nmap-cli 'nmap -sV -sC' # Run nmap on found ports naabu -host corp.lu -top-ports 1000 \ -nmap-cli 'nmap -sV -oX out.xml' # Naabu finds open ports fast; nmap does deep service/version scanning
OUTPUT#
naabu -host corp.lu -o ports.txt # Text output naabu -host corp.lu -json -o ports.json # JSON naabu -list hosts.txt -silent -o open.txt # Pipe-friendly
EXAMPLES#
# Enumerate subdomains, scan their ports, probe live web services subfinder -d corp.lu -silent | naabu -silent | httpx -silent -title # Fast full-port sweep of a scoped host, then nmap service detection naabu -host 192.0.2.10 -p - -rate 3000 \ -nmap-cli 'nmap -sV -sC -oN host.nmap' # Top-1000 across a CIDR, excluding CDN ranges naabu -host 192.0.2.0/24 -top-ports 1000 -exclude-cdn -o open.txt
NOTES#
- Naabu is a discovery scanner, not a service/version scanner - hand off to nmap (-nmap-cli) or httpx for the deep work - SYN scan (-s s) is faster but needs root/CAP_NET_RAW; CONNECT works unprivileged - -exclude-cdn avoids wasting a full-port scan on CDN IPs - Fits between MASSCAN/NMAP (you already have both) as the pipeline- native discovery step feeding httpx/nuclei - Single Go binary - easy to pin in NixOS; respect authorized rate limits on production FS networks