Command library / nmap
nmap
Network mapper: finds hosts, open ports and service versions
Nmap ("Network Mapper") discovers hosts on a network, finds their open ports and can identify the services, versions and operating systems behind them. Scan types are single-dash options whose letters are case-sensitive (-sS, -sV, -sU). Only scan systems you own or have written permission to test.
Practice nmapUsage
Options and flags
targethost name, IP address or CIDR range to scan
-sVservice/version detection on open ports
-sSTCP SYN scan (fast, needs root)
-sTTCP connect scan (no root needed)
-sUUDP scan (slow; needs root)
-sNTCP Null scan (no flags set)
-snping scan: host discovery only, no port scan
-sCrun the default NSE scripts
-p, --portsPORTSports to scan, e.g. 22,80,443 or 1-1000 or - for all 65535
-Pnskip host discovery — treat the host as up (use when ping is blocked)
-Aaggressive: OS detection, version detection, default scripts and traceroute
-OOS detection
-Ffast scan: only the 100 most common ports
-vincrease verbosity
-T0-5timing template: 0 (slowest, stealthy) to 5 (fastest)
--top-portsNscan the N most common ports
--scriptSCRIPTSrun the named NSE scripts or categories
-oNFILEsave results in normal (human-readable) format
-oXFILEsave results as XML
-oABASENAMEsave in all three formats at once
-iLFILEread the target list from a file
Examples
nmap -sV 192.168.1.10Scan the default ports and identify service versions.
nmap -p 22,80,443 10.10.10.5Only three ports — quick and quiet.
nmap -sn 192.168.1.0/24Which hosts on the /24 are alive? No port scan.
nmap -Pn -p- 10.10.10.5All 65535 ports on a host that ignores ping.
nmap -sV -oN scan.txt 10.10.10.5Version scan, results saved to scan.txt.
Common mistakes
Scan-type letters are case-sensitive: `-sv` does not exist, `-sV` is version detection.
`-p` takes a port list; skipping host discovery is `-Pn` with a capital P.