Nmap - Network Enumeration
Cheatsheet
# Scan the full range
rustscan -a 192.168.1.0/24
# Default scan with OS and service detection
sudo rustscan -a 192.168.1.7 -- -A -oA results
# Full TCP scan with service detection and default scripts
sudo nmap <IP> -p- -sV -sC -oA full_tcp
# Top 1000 ports
sudo nmap <IP> -sS -Pn -n -oA quick
# Aggressive scan
sudo nmap <IP> -A -oA aggressive
# UDP scan of the top 100 ports
sudo nmap <IP> -sU -F -oA udp_fast
# Host discovery on a subnet
sudo nmap <NETWORK>/24 -sn -oA discovery
# Host discovery from a file
sudo nmap -sn -iL hosts.lst -oA discovery
# NSE vulnerability scan on one port
sudo nmap <IP> -p <PORT> -sV --script vuln -oA vuln_check
# Firewall evasion with a decoy scan
sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping -D RND:5
# Firewall evasion with source port 53
sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping --source-port 53
# Connect to a filtered port with source port 53
ncat -nv --source-port 53 <IP> <PORT>
# Convert XML output to an HTML report
xsltproc target.xml -o target.htmlMethodology
Phase 1: Host Discovery
Ask yourself
- Which hosts in the target scope are alive?
- Do host firewalls block ICMP echo requests?
- Are the targets on the same subnet? Use ARP ping.
- Are the targets remote? Use ICMP or TCP probes.
- Does a missing response mean the host is down?
- Or did a filter drop the probes?
- If ICMP fails, which other discovery methods should I try?
- Sweep the network range. Use
-snto find live hosts. - Check ARP results on the same subnet. Nmap sends ARP pings automatically when targets are local.
- Retry hosts that appear down. Use TCP SYN to common ports (
-PS22,80,443) or TCP ACK (-PA80). - Scan targets from a list. Use
-iL hosts.lst. - Save discovery results. Use
-oAso you can compare methods. - Record which hosts responded. Non-responders may or may not need more investigation.
# Subnet sweep
sudo nmap 10.129.2.0/24 -sn -oA tnet | grep for | cut -d" " -f5
# IP range shorthand
sudo nmap -sn -oA tnet 10.129.2.18-20
# Force ICMP echo. Disable ARP on the local subnet.
sudo nmap <IP> -sn -PE --disable-arp-ping --packet-trace
# Use --reason to show why Nmap marks a host alive
sudo nmap <IP> -sn -PE --reasonPhase 2: Port Scanning
Ask yourself
- Should I start with a top-ports scan?
- Or should I start with a full port scan?
- Is a SYN scan (
-sS) appropriate? It needs root. - Is a Connect scan (
-sT) appropriate? It does not need root. - Do filtered ports show that a firewall is present?
- How do I tell dropped packets (no response) from rejected packets (RST or ICMP)?
- Did I scan UDP ports? Or only TCP?
- What trade-off between speed and accuracy is acceptable for this engagement?
- Run a fast first scan. Use
-For--top-ports=100/1000. - Start a full TCP port scan. Use
-p-in the background. - Check filtered ports. Use
--packet-traceand--reason. See if the target dropped or rejected the packets. - Run a UDP scan. Use
-sU -F. Administrators often forget UDP filtering. - Record all port states. Record open, closed, filtered, and open|filtered.
- If you have little time, set an order. Finish full TCP first. Then scan common UDP services (53, 67, 68, 69, 123, 137, 138, 161, 500, 514, 1900, 5353).
# SYN scan top 1000 (default, needs root)
sudo nmap <IP> -sS -oA syn_scan
# Connect scan
nmap <IP> -sT -oA connect_scan
# Full port range
sudo nmap <IP> -p- -oA all_ports
# Trace one port to observe firewall behavior
sudo nmap <IP> -p <PORT> --packet-trace -Pn -n --disable-arp-ping
# UDP scan top 100
sudo nmap <IP> -sU -F -oA udp_scanPhase 3: Service Enumeration and Version Detection
Ask yourself
- What exact service and version runs on each open port?
- Does the banner match the Nmap signature result?
- Is Nmap missing information that a manual banner grab would show?
- What OS can I infer from service banners and TTL values?
- Which services are candidates for known CVEs based on their version?
- Fingerprint services. Run
-sVon all open ports. - Grab banners manually. Use
ncorncaton unknown or interesting ports. Catch details that Nmap misses. - Run default scripts. Use
-sCfor extra enumeration that is safe. - Run an aggressive scan if noise is acceptable.
-Acombines-sV,-O,--traceroute, and-sC. - Compare automatic results with manual results. Nmap sometimes truncates banner data.
- Record exact versions for exploit research.
# Service version detection
sudo nmap <IP> -p- -sV -oA versions
# Version detection and default scripts
sudo nmap <IP> -p- -sV -sC -oA full_enum
# Manual banner grab to check results
ncat -nv <IP> <PORT>
# Monitor progress on long scans
sudo nmap <IP> -p- -sV --stats-every=5sPhase 4: NSE Scripts and Vulnerability Assessment
Ask yourself
- Which NSE script categories are safe to run without disrupting services?
- Does the
vulncategory show known CVEs for the detected versions? - Are there scripts for this service that extract extra data?
- Can those scripts list users, shares, or directories?
- What is the OPSEC cost of running intrusive script categories?
- Do script results match what I would expect from the identified version?
- Scan high-value ports for known vulnerabilities. Use
--script vuln. - Use scripts for the specific service. Example:
banner,smtp-commandsfor SMTP. - Avoid
brute,dos,exploit, andintrusive. Run them only when they are explicitly authorized and OPSEC-acceptable. - Compare CVEs from NSE with version data. Check that each CVE applies.
- Record all script output for the report.
# Default safe scripts
sudo nmap <IP> -p <PORT> -sC
# Vulnerability scanning
sudo nmap <IP> -p <PORT> -sV --script vuln
# Specific scripts
sudo nmap <IP> -p 25 --script banner,smtp-commands
# Script category
sudo nmap <IP> --script discoveryPhase 5: Firewall and IDS/IPS Evasion
Ask yourself
- Does the firewall drop filtered ports (no response, long timeout)?
- Or does it reject them (ICMP unreachable, RST, or ICMP error)?
- Does an ACK scan (
-sA) show unfiltered ports that a SYN scan shows as filtered? - Can I bypass firewall rules with source port 53 (DNS)?
- Would decoys or fragmentation help evade IDS detection?
- Is an IPS blocking my scanning IP?
- If the target blocks me, should I switch IP or MAC address?
- Compare SYN scan results with ACK scan results. Map firewall rules.
- Test filtered ports with
--source-port 53. Poorly configured firewalls trust DNS traffic. - Use decoy scans (
-D RND:5). Hide the true source among other addresses. - Scan from a different source IP. Use
-S <IP> -e <interface>to test subnet-based rules. - Fragment packets (
-f). Evade shallow packet inspection. - Use
--data-length <num>. Add data so packets match signatures less often. - If the target blocks a VPS, switch IP or MAC address. This shows an IPS is active.
- Connect to newly found open ports. Use
ncat --source-port 53to check access.
# ACK scan to detect firewall rules
sudo nmap <IP> -p 21,22,25 -sA -Pn -n --disable-arp-ping --packet-trace
# Decoy scan with 5 random IPs
sudo nmap <IP> -p 80 -sS -Pn -n --disable-arp-ping -D RND:5
# Source port 53 to bypass misconfigured firewalls
sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping --source-port 53
# Spoof source IP. You must set the interface.
sudo nmap <IP> -p <PORT> -O -S <SPOOFED_IP> -e tun0
# Check access to a filtered port with source port 53
ncat -nv --source-port 53 <IP> <PORT>
# Specify DNS servers for queries
sudo nmap <IP> --dns-server <NS1>,<NS2>Phase 6: Performance Tuning
Ask yourself
- Is scan speed causing me to miss hosts or ports (false negatives)?
- Am I whitelisted, so I may use aggressive timing?
- Or must I remain below IDS thresholds?
- What is the network bandwidth and latency to the target?
- Is the trade-off between
-T4/-T5speed and possible detection acceptable? - Should I reduce retries or adjust RTT timeouts for this network?
- Speed scans in whitelisted or lab environments. Use
-T4or--min-rate 300. - For stealth, use
-T2or-T1. Accept longer scan times. - Set
--initial-rtt-timeoutand--max-rtt-timeout. Use values based on observed latency. - Reduce
--max-retries(default 10) to increase speed. Accept that you may miss ports. - Always compare fast scans with default scans. Measure what speed costs.
# Aggressive timing
sudo nmap <NETWORK>/24 -F -T4
# Insane timing (lab only)
sudo nmap <NETWORK>/24 -F -T5
# Custom rate. Minimum 300 packets per second.
sudo nmap <NETWORK>/24 -F --min-rate 300
# Reduced RTT for fast networks
sudo nmap <NETWORK>/24 -F --initial-rtt-timeout 50ms --max-rtt-timeout 100ms
# Zero retries. Fastest. May miss ports.
sudo nmap <NETWORK>/24 -F --max-retries 0When the Scan Finds Nothing
Ask yourself
- Did I scan all 65535 TCP ports (
-p-)? - Or did I stop at the top 1000?
- Did I skip UDP? Many footholds (SNMP, TFTP, DNS, IKE) use UDP only.
- Does the host look down only because it blocks ICMP?
- Did I try
-Pn? - Can aggressive timing or low retries cause false negatives?
- Could a firewall drop my SYN packets when another technique would succeed?
- Re-run with
-p- -Pn. Force a full scan even if the host looks down. - Add a UDP scan if you only ran TCP.
- Reduce speed. Use
-T2and default retries. Compare against the fast baseline. - Try other techniques. Use
-sT(no root),-sA(firewall mapping), or--source-port 53. - Switch source IP or VPS if an IPS may have blocked you.
- Check reachability outside Nmap. Use
ping,nc, andtraceroutebefore you assume the host is offline.
OPSEC
Port scanning is noisy. Assume a competent defender can see it. Pick the technique that matches your noise budget.
| Technique | Noise | Telemetry a defender sees |
|---|---|---|
SYN scan (-sS) | Medium | Many half-open connections. IDS signatures (for example Snort or Suricata portscan). Firewall logs. |
Connect scan (-sT) | High | Completed connections in service logs (auth logs, web logs). Netflow. |
Aggressive (-A) | High | Version probes, OS fingerprint packets, NSE traffic, and traceroute. This traffic is very distinctive. |
UDP scan (-sU) | Medium | Bursts of empty datagrams. Slow, sustained traffic that lingers in logs. |
vuln/brute NSE | High–Critical | Exploit or login attempts. May appear as attacks and trigger blocks. |
Decoy (-D) | Medium | Hides the source among spoofed IPs. Volume still flags a portscan. |
-T0/-T1 | Low | Spreads probes over time to remain below IDS thresholds. Costs hours. |
OPSEC. Noise: medium-high. Telemetry: IDS portscan alerts, firewall deny logs, service connection logs, and netflow. Prerequisite: root for -sS, -sU, and -O. Footprint: connection log entries. No persistent change on the target.
Reference
Nmap Architecture
Nmap divides into five core capabilities:
- Host discovery. Determine which targets are alive.
- Port scanning. Identify open, closed, and filtered ports.
- Service enumeration. Fingerprint services and versions.
- OS detection. Identify the operating system.
- NSE. Scriptable interaction with target services.
Syntax
nmap <scan types> <options> <target>Scan Techniques
| Flag | Technique | Use Case |
|---|---|---|
-sS | TCP SYN (half-open) | Default with root. Stealthier than Connect. |
-sT | TCP Connect (full handshake) | No root required. Creates logs on the target. |
-sA | TCP ACK | Firewall rule mapping (not port state). |
-sU | UDP | Stateless. Slow. Administrators often forget it. |
-sN/-sF/-sX | TCP Null/FIN/Xmas | Firewall evasion. Unreliable on Windows. |
-sW | TCP Window | Like ACK, but inspects the RST window field. |
-sI | Idle scan | Fully blind via a zombie host. |
-sO | IP protocol scan | Identify supported IP protocols. |
Port States
| State | Meaning |
|---|---|
open | Connection established (SYN-ACK for TCP, response for UDP). |
closed | RST received. The port is reachable, but no service is listening. |
filtered | No response or ICMP error. A firewall is likely dropping or rejecting traffic. |
unfiltered | ACK scan only. The port is reachable, but open or closed is unknown. |
open|filtered | No response on UDP, Null, FIN, or Xmas. Ambiguous. |
closed|filtered | Idle scan only. Cannot determine state. |
TCP SYN Scan Behavior
- Sends SYN → receives SYN-ACK = open
- Sends SYN → receives RST = closed
- Sends SYN → no response after retries = filtered
Nmap never completes the three-way handshake. Most services do not log a full TCP connection. Advanced IDS or IPS can still detect half-open scans.
TCP Connect Scan Behavior
A Connect scan completes the full three-way handshake. It is more accurate. It also creates connection logs. It behaves like a normal client. That makes it less likely to crash fragile services.
UDP Scan Behavior
- Sends empty datagram → receives UDP response = open
- Sends empty datagram → receives ICMP port unreachable (type 3, code 3) = closed
- Sends empty datagram → no response after retries = open|filtered
UDP scanning is slower than TCP. UDP has no acknowledgment. Timeouts are longer.
OS Detection
-O fingerprints the operating system from TCP/IP stack behavior. It uses packet order, initial sequence numbers, TCP options, and window sizes. It needs root. It is most accurate with at least one open port and one closed port.
# Standalone OS detection
sudo nmap <IP> -O
# More aggressive guessing when there is no exact match
sudo nmap <IP> -O --osscan-guessWhen Nmap cannot find an exact match, it prints percentage-based Aggressive OS guesses. Treat these as hints, not facts. Compare them with reply TTL values and service banners. Approximate TTL values: 64 for Linux or Unix, 128 for Windows, 255 for network gear. OS detection packets are distinctive. Defenders can flag them easily. Run OS detection only when the noise is acceptable.
NSE Script Categories
| Category | Description | OPSEC Risk |
|---|---|---|
auth | Authentication credential checks | Low |
broadcast | Host discovery via broadcast | Medium |
brute | Brute-force login attempts | High |
default | Safe scripts run with -sC | Low |
discovery | Service and network information gathering | Low |
dos | Denial-of-service testing | Critical |
exploit | Active exploitation of known vulnerabilities | Critical |
external | Queries external services (for example whois) | Low |
fuzzer | Protocol fuzzing | High |
intrusive | May crash or disrupt services | High |
malware | Malware infection checks | Low |
safe | Non-intrusive, non-destructive | Low |
version | Extended version detection | Low |
vuln | Vulnerability identification | Medium |
Output Formats
| Flag | Format | Extension | Use |
|---|---|---|---|
-oN | Normal text | .nmap | Human-readable |
-oG | Grepable | .gnmap | Quick parsing with grep/awk |
-oX | XML | .xml | Tool integration, HTML reports |
-oA | All three | all | Always use this |
Convert XML to HTML: xsltproc target.xml -o target.html
Timing Templates
| Template | Name | Use Case |
|---|---|---|
-T0 | Paranoid | IDS evasion. Serialized. 5-minute wait between probes. |
-T1 | Sneaky | IDS evasion. 15-second interval. |
-T2 | Polite | Reduced bandwidth usage. |
-T3 | Normal | Default. |
-T4 | Aggressive | Fast. Reliable networks. |
-T5 | Insane | Lab or whitelisted only. May miss ports. |
Performance Tuning Options
| Option | Effect | Trade-off |
|---|---|---|
--min-rate <n> | Minimum packets per second | May overwhelm slow links |
--max-retries <n> | Retry limit per port (default 10) | Lower is faster but may miss |
--initial-rtt-timeout <ms> | Starting RTT estimate | Too low causes false negatives |
--max-rtt-timeout <ms> | Maximum wait for a response | Too low misses slow hosts |
--host-timeout <time> | Stop scanning a host after this time | Skips unresponsive targets |
--min-parallelism <n> | Minimum parallel probes | Higher is faster and noisier |
Firewall Evasion Techniques
| Technique | Flag | How It Works |
|---|---|---|
| Decoy scan | -D RND:5 | Inserts fake source IPs among real scan packets |
| Source port spoof | --source-port 53 | Uses a trusted port (DNS) as the source |
| Source IP spoof | -S <IP> -e <iface> | Changes the source IP. Responses must route back. |
| Fragmentation | -f | Splits packets into 8-byte fragments |
| MTU control | --mtu <size> | Custom fragment size (must be a multiple of 8) |
| Data length | --data-length <n> | Appends random data to change the packet signature |
| DNS servers | --dns-server <ns> | Use internal DNS servers for resolution |
| Idle scan | -sI <zombie> | Fully blind scan via the IPID of a zombie host |
ACK Scan for Firewall Mapping
The ACK scan (-sA) cannot determine if a port is open or closed. It determines whether a firewall filters or does not filter the port:
- RST response = unfiltered (the firewall allows the packet through)
- No response / ICMP error = filtered (the firewall blocks it)
Compare -sS and -sA results. Identify which ports the firewall protects.
Banner Grabbing Beyond Nmap
Nmap -sV can miss details from service banners. Check banners manually:
# Manual banner grab
nc -nv <IP> <PORT>
# Capture the three-way handshake and banner with tcpdump
sudo tcpdump -i eth0 host <LHOST> and <IP>The PSH-ACK packet after the handshake often contains the full banner. That banner may include OS distribution details that Nmap may truncate.
Service banners can be customized or stripped. Never rely only on banner data for OS or version identification. Compare banners with other evidence. Use TTL values, TCP window sizes, and protocol behavior.
Key Differences: Dropped vs. Rejected Packets
| Behavior | Indicator | What It Means |
|---|---|---|
| Dropped | No response. The scan takes about 2 seconds per port because of retransmissions. | The firewall discards packets with no reply. |
| Rejected | ICMP type 3/code 3 or TCP RST. Fast response. | The firewall denies the packet and notifies the sender. |
Rejected packets show a firewall immediately. Dropped packets waste attacker time. Dropped packets also show filtering if you compare timing.
Knowledge Check
Quiz
Your default Nmap scan of a host returns: Host seems down. If it is really up, but blocking our ping probes, try -Pn. The host is in scope. Other hosts on the subnet respond. What is the best next step?
Quiz
A SYN scan shows TCP/445 as filtered. You need to know whether a firewall is dropping or rejecting the traffic. You also need to know whether any rule lets packets through. Which single technique most directly maps the firewall's behavior?
Quiz
You are scanning a target on a monitored corporate network. You must remain below the IDS radar and still discover services. Which approach best balances stealth with results?
Common Mistakes
Frequent errors
- Run only TCP scans and forget UDP. Critical services (DNS, SNMP, TFTP, NFS) live on UDP.
- Use
-T5on real engagements. This triggers IDS or IPS. You may also miss filtered ports. - Set
--max-retries 0or aggressive RTT timeouts. Do this without a baseline comparison. - Assume “filtered” means “protected.” It means a firewall is present. Bypass paths may still exist.
- Skip
-oA. Comparison and reporting become hard later. - Trust Nmap version detection without a manual banner check.
- Scan without
-Pnwhen targets block ICMP. Nmap marks hosts as down and skips them. - Forget
--source-port 53on filtered ports. Misconfigured firewalls often trust DNS.
Attack Chains / Related Notes
- Leads to: Service enumeration from discovered ports. Then: FTP, SMB, SSH, SMTP, DNS, SNMP
- Leads to: Exploit research from version data. See Exploitation.
- Leads to: Firewall rule mapping for pivot planning. See Lateral Movement.
- Related: Infrastructure Enumeration. Use it for wider recon. Use it for other alive-detection when a control blocks Nmap.