awesome-nmap-grep.md (8967B)
1 --- 2 title: "Awesome NMAP grep" 3 description: "A collection of awesome, _grep-like_ commands for the nmap greppable output (-oG) format. This repository aims to serve as a quick reference to modify theβ¦" 4 category: enumeration 5 tags: ["enumeration"] 6 tools: ["Nmap"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/Awesome NMAP grep.md" 10 upstreamName: "awesome-nmap-grep" 11 upstreamUrl: "https://github.com/leonjza/awesome-nmap-grep" 12 upstreamAuthor: "Leon Jacobs (@leonjza)" 13 upstreamLicense: "none" 14 upstreamRelation: "verbatim" 15 --- 16 # awesome-nmap-grep π₯ 17 18 > Reproduced from [awesome-nmap-grep](https://github.com/leonjza/awesome-nmap-grep) by 19 > **Leon Jacobs** ([@leonjza](https://github.com/leonjza)). All commands, annotations and sample 20 > output are his work. 21 22 A collection of awesome, _grep-like_ commands for the `nmap` greppable output 23 (`-oG`) format. This repository aims to serve as a quick reference to modify the 24 output into readable formats. 25 26 All of the below commands assume the output was saved to a file called 27 `output.grep`. The example command to produce this file as well as the sample 28 outputs was: `nmap -v --reason 127.0.0.1 -sV -oG output.grep -p-`. 29 30 Finally, the `NMAP_FILE` variable is set to contain `output.grep`. 31 32 ## commands 33 34 * [Count Number of Open Ports](#count-number-of-open-ports) 35 * [Top 10 Open Ports](#print-the-top-10-ports) 36 * [Top Service Identifiers](#top-service-identifiers) 37 * [Top Service Names](#top-service-names) 38 * [Hosts and Open Ports](#hosts-and-open-ports) 39 * [Banner Grab](#banner-grab) 40 41 ## count number of open ports 42 43 ### command 44 45 ```bash 46 NMAP_FILE=output.grep 47 48 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \ 49 sed -n -e 's/Ignored.*//p' | \ 50 awk -F, '{split($0,a," "); printf "Host: %-20s Ports Open: %d\n" , a[1], NF}' \ 51 | sort -k 5 -g 52 ``` 53 54 ### output 55 56 ```bash 57 Host: 127.0.0.1 Ports Open: 16 58 ``` 59 60 ### explained 61 62 ```bash 63 $ NMAP_FILE=output.grep 64 65 $ egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \ 66 # | ββββββββ¬βββββββ | | ββ Select the rest of 67 # | | | | the fields which 68 # | | | | will be the open 69 # | | | | ports. 70 # | | | | 71 # | | | ββ Select the second field 72 # | | | to print which will 73 # | | | be IP Address 74 # | | | 75 # | | ββ The file containing the grepable output. 76 # | | 77 # | ββ Ignore lines that start with a # or contain the string 78 # | 'Status: Up' 79 # | 80 # ββ Inverse the pattern match 81 sed -n -e 's/Ignored.*//p' | \ 82 # | | ββββββββ¬ββββββββ 83 # | | ββ Remove text from the string 'Ignored' onwards. 84 # | | 85 # | ββ Specify the script to execute. 86 # | 87 # ββ Be quiet on errors. 88 awk -F, '{split($0,a," "); printf "Host: %-20s Ports Open: %d\n" , a[1], NF}' | \ 89 # | ββββββββ¬βββββββ βββ¬ββ βββ¬ββ | 90 # | | | Use the second element β | 91 # | | | in array a defined by | 92 # | | | the previous split(). | 93 # | | | | 94 # | | | The total columns ββββββ 95 # | | | extracted. 96 # | | | 97 # | | ββ Pad the string to 20 spaces. 98 # | | 99 # | ββ Split the item in the first column again by space, 100 # | storing the resultant array into a. 101 # | 102 # ββ Print a string from a format string 103 sort -k 5 -g 104 ``` 105 106 ## print the top 10 ports 107 108 ### command 109 110 ```bash 111 NMAP_FILE=output.grep 112 113 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f4- | \ 114 sed -n -e 's/Ignored.*//p' | tr ',' '\n' | sed -e 's/^[ \t]*//' | \ 115 sort -n | uniq -c | sort -k 1 -r | head -n 10 116 ``` 117 118 ### output 119 120 ```bash 121 1 9001/open/tcp//tor-orport?/// 122 1 9000/open/tcp//cslistener?/// 123 1 8080/open/tcp//http-proxy/// 124 1 80/open/tcp//http//Caddy/ 125 1 6379/open/tcp//redis//Redis key-value store/ 126 1 631/open/tcp//ipp//CUPS 2.1/ 127 1 6234/open/tcp///// 128 1 58377/filtered/tcp///// 129 1 53/open/tcp//domain//dnsmasq 2.76/ 130 1 49153/open/tcp//mountd//1-3/ 131 ``` 132 133 ### explained 134 135 ```bash 136 $ NMAP_FILE=output.grep 137 138 $ egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f4- | \ 139 # | ββββββββ¬βββββββ | ββ Select only the fields 140 # | | | with the port details. 141 # | | | 142 # | | ββ The file containing the grepable output. 143 # | | 144 # | ββ Ignore lines that start with a # or contain the string 145 # | 'Status: Up' 146 # | 147 # ββ Inverse the pattern match 148 sed -n -e 's/Ignored.*//p' | tr ',' '\n' | sed -e 's/^[ \t]*//' | \ 149 # | | ββββββββ¬ββββββββ ββ¬β βββ¬β βββββββ¬ββββββ 150 # | | | | | ββ Remove tabs and 151 # | | | | | spaces. 152 # | | | | ββ ... with newlines. 153 # | | | | 154 # | | | ββ Replace commas ... 155 # | | | 156 # | | ββ Remove text from the string 'Ignored' onwards. 157 # | | 158 # | ββ Specify the script to execute. 159 # | 160 # ββ Be quiet on errors. 161 sort -n | uniq -c | sort -k 1 -r | head -n 10 162 # | | | ββ Print the first 10 lines. 163 # | | | 164 # | | ββ Output result in reverse 165 # | | 166 # | ββ Count occurrences 167 # | 168 # ββ Sort numerically. 169 ``` 170 171 ## top service identifiers 172 173 ### command 174 175 ```bash 176 NMAP_FILE=output.grep 177 178 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d ' ' -f4- | tr ',' '\n' | \ 179 sed -e 's/^[ \t]*//' | awk -F '/' '{print $7}' | grep -v "^$" | sort | uniq -c \ 180 | sort -k 1 -nr 181 ``` 182 183 ### output 184 185 ```bash 186 2 Caddy 187 2 1-3 (RPC 100005) 188 1 dnsmasq 2.76 189 1 Redis key-value store 190 1 OpenSSH 6.9 (protocol 2.0) 191 1 MySQL 5.5.5-10.1.14-MariaDB 192 1 CUPS 2.1 193 ``` 194 195 ## top service names 196 197 ### command 198 199 ```bash 200 NMAP_FILE=output.grep 201 202 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d ' ' -f4- | tr ',' '\n' | \ 203 sed -e 's/^[ \t]*//' | awk -F '/' '{print $5}' | grep -v "^$" | sort | uniq -c \ 204 | sort -k 1 -nr 205 ``` 206 207 ### output 208 209 ```bash 210 2 mountd 211 2 http 212 1 unknown 213 1 tor-orport? 214 1 ssl|https 215 1 ssh 216 1 redis 217 1 mysql 218 1 ipp 219 1 http-proxy 220 1 domain 221 1 cslistener? 222 ``` 223 224 ## hosts and open ports 225 226 ### command 227 228 ```bash 229 NMAP_FILE=output.grep 230 231 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \ 232 sed -n -e 's/Ignored.*//p' | \ 233 awk '{print "Host: " $1 " Ports: " NF-1; $1=""; for(i=2; i<=NF; i++) { a=a" "$i; }; split(a,s,","); for(e in s) { split(s[e],v,"/"); printf "%-8s %s/%-7s %s\n" , v[2], v[3], v[1], v[5]}; a="" }' 234 ``` 235 236 ### output 237 238 ```bash 239 Host: 127.0.0.1 Ports: 16 240 open tcp/22 ssh 241 open tcp/53 domain 242 open tcp/80 http 243 open tcp/443 https 244 open tcp/631 ipp 245 open tcp/3306 mysql 246 open tcp/4767 unknown 247 open tcp/6379 248 open tcp/8080 http-proxy 249 open tcp/8081 blackice-icecap 250 open tcp/9000 cslistener 251 open tcp/9001 tor-orport 252 open tcp/49152 unknown 253 open tcp/49153 unknown 254 filtered tcp/54695 255 filtered tcp/58369 256 ``` 257 258 ## banner grab 259 260 ### command 261 262 ```bash 263 NMAP_FILE=output.grep 264 265 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \ 266 awk -F, '{split($1,a," "); split(a[2],b,"/"); print a[1] " " b[1]; for(i=2; i<=NF; i++) { split($i,c,"/"); print a[1] c[1] }}' \ 267 | xargs -L1 nc -v -w1 268 ``` 269 270 ### output 271 272 *Sample* 273 274 ```bash 275 found 0 associations 276 found 1 connections: 277 1: flags=82<CONNECTED,PREFERRED> 278 outif lo0 279 src 127.0.0.1 port 52224 280 dst 127.0.0.1 port 3306 281 rank info not available 282 TCP aux info available 283 284 Connection to 127.0.0.1 port 3306 [tcp/mysql] succeeded! 285 Y 286 5.5.5-10.1.14-MariaDBοΏ½uds9^MIfοΏ½οΏ½!?οΏ½EgVZ>iv7KTD7mysql_native_passwordfound 0 associations 287 288 nc: connectx to 127.0.0.1 port 54695 (tcp) failed: Connection refused 289 nc: connectx to 127.0.0.1 port 58369 (tcp) failed: Connection refused 290 ```