daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

awesome-nmap-grep.md (8967B)


      1 ---
      2 title: "Awesome NMAP grep"
      3 description: "A collection of awesome, _grep-like_ commands for the nmap greppable output (-oG) format. This repository aims to serve as a quick reference to modify the…"
      4 category: enumeration
      5 tags: ["enumeration"]
      6 tools: ["Nmap"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/Awesome NMAP grep.md"
     10 upstreamName: "awesome-nmap-grep"
     11 upstreamUrl: "https://github.com/leonjza/awesome-nmap-grep"
     12 upstreamAuthor: "Leon Jacobs (@leonjza)"
     13 upstreamLicense: "none"
     14 upstreamRelation: "verbatim"
     15 ---
     16 # awesome-nmap-grep πŸ’₯
     17 
     18 > Reproduced from [awesome-nmap-grep](https://github.com/leonjza/awesome-nmap-grep) by
     19 > **Leon Jacobs** ([@leonjza](https://github.com/leonjza)). All commands, annotations and sample
     20 > output are his work.
     21 
     22 A collection of awesome, _grep-like_ commands for the `nmap` greppable output
     23 (`-oG`) format. This repository aims to serve as a quick reference to modify the
     24  output into readable formats.
     25 
     26 All of the below commands assume the output was saved to a file called
     27 `output.grep`. The example command to produce this file as well as the sample
     28 outputs was: `nmap -v --reason 127.0.0.1 -sV -oG output.grep -p-`.
     29 
     30 Finally, the `NMAP_FILE` variable is set to contain `output.grep`.
     31 
     32 ## commands
     33 
     34 * [Count Number of Open Ports](#count-number-of-open-ports)
     35 * [Top 10 Open Ports](#print-the-top-10-ports)
     36 * [Top Service Identifiers](#top-service-identifiers)
     37 * [Top Service Names](#top-service-names)
     38 * [Hosts and Open Ports](#hosts-and-open-ports)
     39 * [Banner Grab](#banner-grab)
     40 
     41 ## count number of open ports
     42 
     43 ### command
     44 
     45 ```bash
     46 NMAP_FILE=output.grep
     47 
     48 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \
     49 sed -n -e 's/Ignored.*//p' | \
     50 awk -F, '{split($0,a," "); printf "Host: %-20s Ports Open: %d\n" , a[1], NF}' \
     51 | sort -k 5 -g
     52 ```
     53 
     54 ### output
     55 
     56 ```bash
     57 Host: 127.0.0.1            Ports Open: 16
     58 ```
     59 
     60 ### explained
     61 
     62 ```bash
     63 $ NMAP_FILE=output.grep
     64 
     65 $ egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \
     66 #        | β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜      |                  |  └─ Select the rest of
     67 #        |        |             |                  |      the fields which
     68 #        |        |             |                  |      will be the open
     69 #        |        |             |                  |      ports.
     70 #        |        |             |                  |
     71 #        |        |             |                  └─ Select the second field
     72 #        |        |             |                      to print which will
     73 #        |        |             |                      be IP Address
     74 #        |        |             |
     75 #        |        |             └─ The file containing the grepable output.
     76 #        |        |
     77 #        |        └─ Ignore lines that start with a # or contain the string
     78 #        |            'Status: Up'
     79 #        |
     80 #        └─ Inverse the pattern match
     81     sed -n -e 's/Ignored.*//p' | \
     82 #        |  | β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜
     83 #        |  |        └─ Remove text from the string 'Ignored' onwards.
     84 #        |  |
     85 #        |  └─ Specify the script to execute.
     86 #        |
     87 #        └─ Be quiet on errors.
     88     awk -F, '{split($0,a," "); printf "Host: %-20s Ports Open: %d\n" , a[1], NF}' | \
     89 #        |    β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜                β””β”€β”¬β”€β”˜                     β””β”€β”¬β”€β”˜ |
     90 #        |           |                         |  Use the second element β”˜   |
     91 #        |           |                         |   in array a defined by     |
     92 #        |           |                         |   the previous split().     |
     93 #        |           |                         |                             |
     94 #        |           |                         |      The total columns β”€β”€β”€β”€β”€β”˜
     95 #        |           |                         |        extracted.
     96 #        |           |                         |
     97 #        |           |                         └─ Pad the string to 20 spaces.
     98 #        |           |
     99 #        |           └─ Split the item in the first column again by space,
    100 #        |               storing the resultant array into a.
    101 #        |
    102 #        └─ Print a string from a format string
    103     sort -k 5 -g
    104 ```
    105 
    106 ## print the top 10 ports
    107 
    108 ### command
    109 
    110 ```bash
    111 NMAP_FILE=output.grep
    112 
    113 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f4- | \
    114 sed -n -e 's/Ignored.*//p' | tr ',' '\n' | sed -e 's/^[ \t]*//' | \
    115 sort -n | uniq -c | sort -k 1 -r | head -n 10
    116 ```
    117 
    118 ### output
    119 
    120 ```bash
    121 1 9001/open/tcp//tor-orport?///
    122 1 9000/open/tcp//cslistener?///
    123 1 8080/open/tcp//http-proxy///
    124 1 80/open/tcp//http//Caddy/
    125 1 6379/open/tcp//redis//Redis key-value store/
    126 1 631/open/tcp//ipp//CUPS 2.1/
    127 1 6234/open/tcp/////
    128 1 58377/filtered/tcp/////
    129 1 53/open/tcp//domain//dnsmasq 2.76/
    130 1 49153/open/tcp//mountd//1-3/
    131 ```
    132 
    133 ### explained
    134 
    135 ```bash
    136 $ NMAP_FILE=output.grep
    137 
    138 $ egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f4- | \
    139 #        | β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜      |                  └─ Select only the fields
    140 #        |        |             |                      with the port details.
    141 #        |        |             |
    142 #        |        |             └─ The file containing the grepable output.
    143 #        |        |
    144 #        |        └─ Ignore lines that start with a # or contain the string
    145 #        |            'Status: Up'
    146 #        |
    147 #        └─ Inverse the pattern match
    148     sed -n -e 's/Ignored.*//p' | tr ',' '\n' | sed -e 's/^[ \t]*//' |  \
    149 #        |  | β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜      β””β”¬β”˜ β””β”€β”¬β”˜          β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
    150 #        |  |        |               |    |                 └─ Remove tabs and
    151 #        |  |        |               |    |                      spaces.
    152 #        |  |        |               |    └─ ... with newlines.
    153 #        |  |        |               |
    154 #        |  |        |               └─ Replace commas ...
    155 #        |  |        |
    156 #        |  |        └─ Remove text from the string 'Ignored' onwards.
    157 #        |  |
    158 #        |  └─ Specify the script to execute.
    159 #        |
    160 #        └─ Be quiet on errors.
    161     sort -n | uniq -c | sort -k 1 -r | head -n 10
    162 #         |         |              |           └─ Print the first 10 lines.
    163 #         |         |              |
    164 #         |         |              └─ Output result in reverse
    165 #         |         |
    166 #         |         └─ Count occurrences
    167 #         |
    168 #         └─ Sort numerically.
    169 ```
    170 
    171 ## top service identifiers
    172 
    173 ### command
    174 
    175 ```bash
    176 NMAP_FILE=output.grep
    177 
    178 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d ' ' -f4- | tr ',' '\n' | \
    179 sed -e 's/^[ \t]*//' | awk -F '/' '{print $7}' | grep -v "^$" | sort | uniq -c \
    180 | sort -k 1 -nr
    181 ```
    182 
    183 ### output
    184 
    185 ```bash
    186 2 Caddy
    187 2 1-3 (RPC 100005)
    188 1 dnsmasq 2.76
    189 1 Redis key-value store
    190 1 OpenSSH 6.9 (protocol 2.0)
    191 1 MySQL 5.5.5-10.1.14-MariaDB
    192 1 CUPS 2.1
    193 ```
    194 
    195 ## top service names
    196 
    197 ### command
    198 
    199 ```bash
    200 NMAP_FILE=output.grep
    201 
    202 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d ' ' -f4- | tr ',' '\n' | \
    203 sed -e 's/^[ \t]*//' | awk -F '/' '{print $5}' | grep -v "^$" | sort | uniq -c \
    204 | sort -k 1 -nr
    205 ```
    206 
    207 ### output
    208 
    209 ```bash
    210 2 mountd
    211 2 http
    212 1 unknown
    213 1 tor-orport?
    214 1 ssl|https
    215 1 ssh
    216 1 redis
    217 1 mysql
    218 1 ipp
    219 1 http-proxy
    220 1 domain
    221 1 cslistener?
    222 ```
    223 
    224 ## hosts and open ports
    225 
    226 ### command
    227 
    228 ```bash
    229 NMAP_FILE=output.grep
    230 
    231 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \
    232 sed -n -e 's/Ignored.*//p'  | \
    233 awk '{print "Host: " $1 " Ports: " NF-1; $1=""; for(i=2; i<=NF; i++) { a=a" "$i; }; split(a,s,","); for(e in s) { split(s[e],v,"/"); printf "%-8s %s/%-7s %s\n" , v[2], v[3], v[1], v[5]}; a="" }'
    234 ```
    235 
    236 ### output
    237 
    238 ```bash
    239 Host: 127.0.0.1 Ports: 16
    240 open     tcp/22    ssh
    241 open     tcp/53    domain
    242 open     tcp/80    http
    243 open     tcp/443   https
    244 open     tcp/631   ipp
    245 open     tcp/3306  mysql
    246 open     tcp/4767  unknown
    247 open     tcp/6379
    248 open     tcp/8080  http-proxy
    249 open     tcp/8081  blackice-icecap
    250 open     tcp/9000  cslistener
    251 open     tcp/9001  tor-orport
    252 open     tcp/49152 unknown
    253 open     tcp/49153 unknown
    254 filtered tcp/54695
    255 filtered tcp/58369
    256 ```
    257 
    258 ## banner grab
    259 
    260 ### command
    261 
    262 ```bash
    263 NMAP_FILE=output.grep
    264 
    265 egrep -v "^#|Status: Up" $NMAP_FILE | cut -d' ' -f2,4- | \
    266 awk -F, '{split($1,a," "); split(a[2],b,"/"); print a[1] " " b[1]; for(i=2; i<=NF; i++) { split($i,c,"/"); print a[1] c[1] }}' \
    267  | xargs -L1 nc -v -w1
    268 ```
    269 
    270 ### output
    271 
    272 *Sample*
    273 
    274 ```bash
    275 found 0 associations
    276 found 1 connections:
    277      1: flags=82<CONNECTED,PREFERRED>
    278     outif lo0
    279     src 127.0.0.1 port 52224
    280     dst 127.0.0.1 port 3306
    281     rank info not available
    282     TCP aux info available
    283 
    284 Connection to 127.0.0.1 port 3306 [tcp/mysql] succeeded!
    285 Y
    286 5.5.5-10.1.14-MariaDBοΏ½uds9^MIfοΏ½οΏ½!?οΏ½EgVZ>iv7KTD7mysql_native_passwordfound 0 associations
    287 
    288 nc: connectx to 127.0.0.1 port 54695 (tcp) failed: Connection refused
    289 nc: connectx to 127.0.0.1 port 58369 (tcp) failed: Connection refused
    290 ```