← All cheat sheets

NMAP

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tools: Recon / OSINT Helper, Nmap Command Builder

BASIC SCANS#

nmap <target>                    # Basic scan (top 1000 ports)
nmap -sn <target>                # Ping scan (host discovery only)
nmap -Pn <target>                # Skip host discovery, treat as online
nmap -p- <target>                # Scan all 65535 ports
nmap -p 22,80,443 <target>       # Scan specific ports
nmap -p 1-1000 <target>          # Scan port range

SCAN TYPES#

nmap -sS <target>                # SYN scan (stealth, default with root)
nmap -sT <target>                # TCP connect scan (no root needed)
nmap -sU <target>                # UDP scan
nmap -sA <target>                # ACK scan (firewall detection)
nmap -sW <target>                # Window scan
nmap -sN <target>                # TCP Null scan
nmap -sF <target>                # FIN scan
nmap -sX <target>                # Xmas scan

SERVICE & VERSION DETECTION#

nmap -sV <target>                # Service version detection
nmap -sV --version-intensity 5   # More aggressive version detection
nmap -sV --version-all <target>  # Try all probes
nmap -O <target>                 # OS detection
nmap -A <target>                 # Aggressive (OS, version, script, traceroute)

TIMING & PERFORMANCE#

nmap -T0 <target>                # Paranoid (IDS evasion)
nmap -T1 <target>                # Sneaky
nmap -T2 <target>                # Polite
nmap -T3 <target>                # Normal (default)
nmap -T4 <target>                # Aggressive
nmap -T5 <target>                # Insane
nmap --max-retries 1 <target>    # Limit retries
nmap --min-rate 1000 <target>    # Send at least 1000 packets/sec

NSE SCRIPTS#

nmap --script=<script> <target>           # Run specific script
nmap --script=default <target>            # Run default scripts
nmap --script=vuln <target>               # Run vulnerability scripts
nmap --script=safe <target>               # Run safe scripts
nmap --script=auth <target>               # Authentication scripts
nmap --script=discovery <target>          # Discovery scripts
nmap --script-args=<args>                 # Pass args to scripts

COMMON SCRIPT EXAMPLES#

nmap --script=http-enum <target>          # Enumerate web directories
nmap --script=smb-vuln* <target>          # SMB vulnerability check
nmap --script=ssl-heartbleed <target>     # Heartbleed check
nmap --script=dns-brute <target>          # DNS brute force
nmap --script=ftp-anon <target>           # Anonymous FTP check
nmap --script=ssh-brute <target>          # SSH brute force

OUTPUT FORMATS#

nmap -oN output.txt <target>     # Normal output
nmap -oX output.xml <target>     # XML output
nmap -oG output.gnmap <target>   # Grepable output
nmap -oA output <target>         # All formats
nmap -v <target>                 # Verbose
nmap -vv <target>                # Very verbose

EVASION & SPOOFING#

nmap -f <target>                 # Fragment packets
nmap --mtu 24 <target>           # Set MTU
nmap -D RND:5 <target>           # Decoy scan with random IPs
nmap -D decoy1,decoy2 <target>   # Decoy scan with specific IPs
nmap -S <spoofed-ip> <target>    # Spoof source IP
nmap -g 53 <target>              # Use source port 53
nmap --data-length 25 <target>   # Append random data

TARGET SPECIFICATION#

nmap 192.168.1.1                 # Single host
nmap 192.168.1.1 192.168.1.2     # Multiple hosts
nmap 192.168.1.1-254             # Range
nmap 192.168.1.0/24              # CIDR notation
nmap -iL targets.txt             # From file
nmap --exclude 192.168.1.1       # Exclude host
nmap --excludefile exclude.txt   # Exclude from file

USEFUL COMBINATIONS#

# Quick scan of common ports
nmap -F -T4 <target>

# Full TCP scan with versions
nmap -sV -sC -p- <target>

# Comprehensive scan
nmap -sS -sV -sC -O -p- -T4 <target>

# Stealth scan
nmap -sS -Pn -T2 -f <target>

# UDP top ports
nmap -sU --top-ports 100 <target>

# Vulnerability assessment
nmap -sV --script=vuln <target>

GREP EXAMPLES#

# Extract open ports
grep "open" output.gnmap | cut -d" " -f2

# Extract IPs with specific port open
grep "80/open" output.gnmap | cut -d" " -f2