โ† All cheat sheets

NAABU

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Nmap Command Builder

OVERVIEW#

Naabu (ProjectDiscovery) is a fast SYN/CONNECT port scanner focused on
reliability and pipeline integration. It pairs with subfinder/httpx and
can hand off discovered ports to nmap for service detection. Authorized
scope only.

BASIC USAGE#

naabu -host corp.lu                            # Scan a host (top ports)
naabu -host 192.0.2.10                          # Scan an IP
naabu -list hosts.txt                           # Hosts from a file
subfinder -d corp.lu -silent | naabu            # From a pipe
naabu -host corp.lu -silent                     # Clean output for pipes

PORT SELECTION#

naabu -host corp.lu -p 80,443,8080              # Specific ports
naabu -host corp.lu -p -                         # All 65535 ports
naabu -host corp.lu -top-ports 100              # Top 100 ports
naabu -host corp.lu -top-ports 1000             # Top 1000
naabu -host corp.lu -ep 80,443                   # Exclude ports
naabu -host corp.lu -pf portlist.txt            # Ports from file

SCAN TYPE & PERFORMANCE#

naabu -host corp.lu -s s                          # SYN scan (needs root)
naabu -host corp.lu -s c                          # CONNECT scan
naabu -host corp.lu -rate 2000                    # Packets/sec
naabu -host corp.lu -c 50                          # Concurrency
naabu -host corp.lu -retries 2 -timeout 1000      # Reliability tuning
naabu -host corp.lu -warm-up-time 2

HOST DISCOVERY / PROBES#

naabu -host corp.lu -sn                            # Ping/host discovery only
naabu -host corp.lu -Pn                            # Skip host discovery
naabu -host corp.lu -exclude-cdn                   # Skip CDN full-port scans

NMAP HANDOFF#

naabu -host corp.lu -nmap-cli 'nmap -sV -sC'      # Run nmap on found ports
naabu -host corp.lu -top-ports 1000 \
  -nmap-cli 'nmap -sV -oX out.xml'
# Naabu finds open ports fast; nmap does deep service/version scanning

OUTPUT#

naabu -host corp.lu -o ports.txt                   # Text output
naabu -host corp.lu -json -o ports.json            # JSON
naabu -list hosts.txt -silent -o open.txt          # Pipe-friendly

EXAMPLES#

# Enumerate subdomains, scan their ports, probe live web services
subfinder -d corp.lu -silent | naabu -silent | httpx -silent -title

# Fast full-port sweep of a scoped host, then nmap service detection
naabu -host 192.0.2.10 -p - -rate 3000 \
  -nmap-cli 'nmap -sV -sC -oN host.nmap'

# Top-1000 across a CIDR, excluding CDN ranges
naabu -host 192.0.2.0/24 -top-ports 1000 -exclude-cdn -o open.txt

NOTES#

- Naabu is a discovery scanner, not a service/version scanner - hand
  off to nmap (-nmap-cli) or httpx for the deep work
- SYN scan (-s s) is faster but needs root/CAP_NET_RAW; CONNECT works
  unprivileged
- -exclude-cdn avoids wasting a full-port scan on CDN IPs
- Fits between MASSCAN/NMAP (you already have both) as the pipeline-
  native discovery step feeding httpx/nuclei
- Single Go binary - easy to pin in NixOS; respect authorized rate
  limits on production FS networks