← All cheat sheets

RUSTSCAN

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Nmap Command Builder

OVERVIEW#

RustScan is a fast port scanner written in Rust that scans all 65535
ports in seconds, then automatically pipes open ports into nmap for
service/version detection. Positions itself as the fast front-end to
nmap. Authorized scope only.

BASIC USAGE#

rustscan -a 192.0.2.10                          # Scan a host (all ports)
rustscan -a corp.lu                             # Scan by hostname
rustscan -a 192.0.2.0/24                         # Scan a CIDR
rustscan -a 192.0.2.10,192.0.2.20               # Multiple targets
rustscan -a hosts.txt                            # (via addresses list)

PORT SELECTION#

rustscan -a 192.0.2.10 -p 80,443,8080           # Specific ports
rustscan -a 192.0.2.10 --range 1-1024           # Port range
rustscan -a 192.0.2.10 --top                      # Nmap top ports

PERFORMANCE / RELIABILITY#

rustscan -a 192.0.2.10 -b 2000                   # Batch size (sockets)
rustscan -a 192.0.2.10 -t 2000                   # Timeout (ms)
rustscan -a 192.0.2.10 --tries 2                  # Retries
rustscan -a 192.0.2.10 -u 5000                    # Ulimit (open files)
# Lower batch size on unstable/rate-limited networks

NMAP HANDOFF (-- SEPARATOR)#

rustscan -a 192.0.2.10 -- -sV -sC                # Pass nmap args after --
rustscan -a 192.0.2.10 -- -A -oN scan.nmap       # Aggressive + output
rustscan -a 192.0.2.10 -- -sV --script vuln      # NSE vuln scripts
rustscan -a 192.0.2.10 -p 445 -- -sV --script smb-*
# Everything after -- is handed verbatim to nmap on the open ports

OUTPUT & MODES#

rustscan -a 192.0.2.10 -g                          # Greppable output
rustscan -a 192.0.2.10 --accessible                # Screen-reader friendly
rustscan -a 192.0.2.10 --no-nmap                    # Ports only, skip nmap
rustscan -a 192.0.2.10 -c config.toml               # Custom config file

DOCKER#

docker run -it --rm rustscan/rustscan:latest -a 192.0.2.10 -- -sV

EXAMPLES#

# Fast full-port sweep, then nmap service + default scripts
rustscan -a 192.0.2.10 -- -sV -sC -oN host.nmap

# CIDR discovery, ports only (feed elsewhere), tuned batch for stability
rustscan -a 192.0.2.0/24 --no-nmap -b 1500 -g -o open.txt

# Targeted SMB deep-dive with NSE
rustscan -a 192.0.2.10 -p 445 -- -sV --script "smb-vuln-*"

NOTES#

- RustScan's value: find open ports in seconds, then let nmap do the
  deep work - it is a front-end, not an nmap replacement
- Tune -b (batch) and -u (ulimit) down on fragile or monitored FS
  networks to avoid tripping rate limits / IDS
- You already have NMAP and MASSCAN; RustScan slots in when you want
  nmap depth with much faster port discovery on single hosts
- Rust single binary - fits a reproducible NixOS toolchain and your
  Rust-tool preference
- Everything after -- is raw nmap syntax (see your NMAP sheet)