NMAP
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tools: Recon / OSINT Helper, Nmap Command Builder
BASIC SCANS#
nmap <target> # Basic scan (top 1000 ports) nmap -sn <target> # Ping scan (host discovery only) nmap -Pn <target> # Skip host discovery, treat as online nmap -p- <target> # Scan all 65535 ports nmap -p 22,80,443 <target> # Scan specific ports nmap -p 1-1000 <target> # Scan port range
SCAN TYPES#
nmap -sS <target> # SYN scan (stealth, default with root) nmap -sT <target> # TCP connect scan (no root needed) nmap -sU <target> # UDP scan nmap -sA <target> # ACK scan (firewall detection) nmap -sW <target> # Window scan nmap -sN <target> # TCP Null scan nmap -sF <target> # FIN scan nmap -sX <target> # Xmas scan
SERVICE & VERSION DETECTION#
nmap -sV <target> # Service version detection nmap -sV --version-intensity 5 # More aggressive version detection nmap -sV --version-all <target> # Try all probes nmap -O <target> # OS detection nmap -A <target> # Aggressive (OS, version, script, traceroute)
TIMING & PERFORMANCE#
nmap -T0 <target> # Paranoid (IDS evasion) nmap -T1 <target> # Sneaky nmap -T2 <target> # Polite nmap -T3 <target> # Normal (default) nmap -T4 <target> # Aggressive nmap -T5 <target> # Insane nmap --max-retries 1 <target> # Limit retries nmap --min-rate 1000 <target> # Send at least 1000 packets/sec
NSE SCRIPTS#
nmap --script=<script> <target> # Run specific script nmap --script=default <target> # Run default scripts nmap --script=vuln <target> # Run vulnerability scripts nmap --script=safe <target> # Run safe scripts nmap --script=auth <target> # Authentication scripts nmap --script=discovery <target> # Discovery scripts nmap --script-args=<args> # Pass args to scripts
COMMON SCRIPT EXAMPLES#
nmap --script=http-enum <target> # Enumerate web directories nmap --script=smb-vuln* <target> # SMB vulnerability check nmap --script=ssl-heartbleed <target> # Heartbleed check nmap --script=dns-brute <target> # DNS brute force nmap --script=ftp-anon <target> # Anonymous FTP check nmap --script=ssh-brute <target> # SSH brute force
OUTPUT FORMATS#
nmap -oN output.txt <target> # Normal output nmap -oX output.xml <target> # XML output nmap -oG output.gnmap <target> # Grepable output nmap -oA output <target> # All formats nmap -v <target> # Verbose nmap -vv <target> # Very verbose
EVASION & SPOOFING#
nmap -f <target> # Fragment packets nmap --mtu 24 <target> # Set MTU nmap -D RND:5 <target> # Decoy scan with random IPs nmap -D decoy1,decoy2 <target> # Decoy scan with specific IPs nmap -S <spoofed-ip> <target> # Spoof source IP nmap -g 53 <target> # Use source port 53 nmap --data-length 25 <target> # Append random data
TARGET SPECIFICATION#
nmap 192.168.1.1 # Single host nmap 192.168.1.1 192.168.1.2 # Multiple hosts nmap 192.168.1.1-254 # Range nmap 192.168.1.0/24 # CIDR notation nmap -iL targets.txt # From file nmap --exclude 192.168.1.1 # Exclude host nmap --excludefile exclude.txt # Exclude from file
USEFUL COMBINATIONS#
# Quick scan of common ports nmap -F -T4 <target> # Full TCP scan with versions nmap -sV -sC -p- <target> # Comprehensive scan nmap -sS -sV -sC -O -p- -T4 <target> # Stealth scan nmap -sS -Pn -T2 -f <target> # UDP top ports nmap -sU --top-ports 100 <target> # Vulnerability assessment nmap -sV --script=vuln <target>
GREP EXAMPLES#
# Extract open ports grep "open" output.gnmap | cut -d" " -f2 # Extract IPs with specific port open grep "80/open" output.gnmap | cut -d" " -f2