daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nmap-nse-scripts.md (13299B)


      1 ---
      2 title: "Nmap NSE Scripts (2026)"
      3 description: "Operator quick reference for selecting, running, constraining and troubleshooting Nmap NSE scripts by category and target service."
      4 category: enumeration
      5 tags: ["enumeration", "port-scanning", "network"]
      6 tools: ["Nmap"]
      7 difficulty: intermediate
      8 updated: "2026-08-28"
      9 source: "vault:Enumeration/Nmap NSE Scripts Cheatsheet 2026.md"
     10 ---
     11 > [!important]+ Purpose
     12 > This is the compact, action-first NSE sheet: how to select, review, run, constrain, and troubleshoot scripts during an authorized assessment. For detailed per-port write-ups and example output, use NSE Guide. Pair with Nmap Cheatsheet 2026 and Common Ports and Services Cheatsheet 2026.
     13 
     14 > [!danger]+ NSE Executes Code
     15 > NSE scripts are Lua programs and are **not sandboxed**. Category labels describe intent; they are not a guarantee of safety. Audit third-party scripts and review `--script-help` before using `intrusive`, `brute`, `vuln`, `exploit`, `dos`, or `fuzzer` against anything sensitive.
     16 
     17 ---
     18 
     19 ## The 60-Second Workflow
     20 
     21 ```bash
     22 # 1. Find the service and version first
     23 nmap -Pn -n -sV -p443 <target>
     24 
     25 # 2. Inspect candidate scripts before executing them
     26 nmap --script-help 'http-title,ssl-cert,ssl-enum-ciphers'
     27 
     28 # 3. Run an explicit, reviewable bundle and save evidence
     29 nmap -Pn -n -sV -p443 \
     30   --script=http-title,http-headers,ssl-cert,ssl-enum-ciphers \
     31   <target> -oA nse-https
     32 
     33 # 4. Trace only when output is missing or surprising
     34 nmap -Pn -n -p443 --script=ssl-cert --script-trace <target>
     35 ```
     36 
     37 > [!tip]+ Explicit Names Beat Giant Categories
     38 > `--script=vuln` is easy to type but difficult to review and reproduce. A comma-separated list records exactly what was approved and run. Use categories for discovery, then narrow the final evidence command to named scripts.
     39 
     40 ---
     41 
     42 ## Selection Syntax
     43 
     44 | Syntax | Meaning |
     45 |---|---|
     46 | `-sC` | Run the curated `default` category |
     47 | `--script=default` | Same script selection as `-sC` |
     48 | `--script=http-title` | One named script |
     49 | `--script=http-title,ssl-cert` | Multiple names/categories (logical OR) |
     50 | `--script='http-*'` | All matching script names; quote the shell wildcard |
     51 | `--script='default or safe'` | Scripts in either category |
     52 | `--script='default and safe'` | Scripts present in both categories |
     53 | `--script='(default or safe) and not broadcast'` | Boolean selection with exclusion |
     54 | `--script='+http-title'` | Force a script even if its run rule would not select the port |
     55 | `--script=/path/check.nse` | Run a trusted script by file path |
     56 | `--script-help <expression>` | Show names, categories, and descriptions without scanning |
     57 
     58 > [!warning]+ The `+` Prefix Bypasses a Safety Check
     59 > A script's `portrule`/`hostrule` normally decides whether it applies. Forcing execution is useful on non-standard ports, but first add `-sV` and verify the detected service. Do not use `+` merely because a script produced no output.
     60 
     61 ---
     62 
     63 ## Script Categories by Operational Risk
     64 
     65 | Category | Typical Purpose | Starting Assumption |
     66 |---|---|---|
     67 | `default` | Curated useful/fast/reliable checks | Usually a reasonable first pass |
     68 | `safe` | Intended not to exploit, crash, or consume excessive resources | Low impact, not zero traffic |
     69 | `version` | Enhances service/version detection | Usually low impact |
     70 | `discovery` | Finds hosts, services, names, or configuration | Review scope expansion and query volume |
     71 | `broadcast` | Local multicast/broadcast discovery | Can discover targets outside the original list |
     72 | `auth` | Authentication configuration or bypass checks | May generate login/security events |
     73 | `external` | Sends information to an external service | Privacy/data-handling review required |
     74 | `vuln` | Tests for known vulnerabilities | Mixed; read each script description |
     75 | `intrusive` | Higher traffic, state changes, or resource use possible | Explicit approval and maintenance awareness |
     76 | `brute` | Repeated credential attempts | Lockout, alerting, and audit-log risk |
     77 | `exploit` | Attempts exploitation | High risk; explicit RoE |
     78 | `dos` | Tests denial-of-service conditions | Never run casually against live services |
     79 | `fuzzer` | Sends malformed/unexpected inputs | Crash/state-corruption risk |
     80 | `malware` | Detects malware/backdoors | Read implementation; behaviour varies |
     81 
     82 ```bash
     83 # Review everything selected by an expression without touching a target
     84 nmap --script-help '(default or safe) and not external'
     85 
     86 # Controlled low-impact starting point
     87 nmap -sV --script='default or safe' <target>
     88 ```
     89 
     90 ---
     91 
     92 ## Script Arguments
     93 
     94 ```bash
     95 # Inline comma-separated key/value pairs: quote the whole expression
     96 nmap -p80 --script=http-title \
     97   --script-args='http.host=app.example.test' <target>
     98 
     99 # SMB authentication
    100 nmap -p445 --script=smb-enum-shares \
    101   --script-args='smbdomain=ACME,smbusername=alice,smbpassword=Password123!' \
    102   <target>
    103 
    104 # SNMP community supplied as an empty username plus password/community
    105 sudo nmap -sU -p161 --script=snmp-info,snmp-sysdescr \
    106   --script-args='creds.snmp=:public' <target>
    107 
    108 # Prefer a file when values need complex quoting or should not sit in history
    109 nmap -p445 --script=smb-enum-shares \
    110   --script-args-file nse-args.txt <target>
    111 ```
    112 
    113 > [!warning]+ Credential Handling
    114 > Command-line secrets may appear in shell history and process listings. Use dedicated assessment credentials, protect argument files, remove them according to the evidence-handling plan, and prefer Kerberos/ticket workflows where the script supports them.
    115 
    116 ### Useful Global Controls
    117 
    118 | Option | Purpose |
    119 |---|---|
    120 | `--script-args='k=v,...'` | Supply script arguments inline |
    121 | `--script-args-file file` | Load arguments from a file |
    122 | `--script-timeout 30s` | Stop an individual script after the limit |
    123 | `--script-trace` | Show data sent and received by scripts |
    124 | `--script-help expression` | Review matching script documentation |
    125 | `--script-updatedb` | Rebuild `script.db` after adding/removing scripts |
    126 | `-d` / `-d2` | Add Nmap/NSE debug information |
    127 | `-oA basename` | Save normal, XML, and greppable evidence |
    128 
    129 ---
    130 
    131 ## Protocol Bundles — Review Before Use
    132 
    133 > [!note]+ Adjust Ports to the Detected Service
    134 > The ports below are defaults, not requirements. Run `-sV`, then target the actual service wherever it is listening. Most examples favor `safe`/`discovery` scripts, but specifically marked follow-ups include `auth` or `intrusive` scripts.
    135 
    136 ### FTP — TCP 21
    137 
    138 ```bash
    139 nmap -sV -p21 --script=ftp-anon,ftp-syst,ftp-bounce <target>
    140 ```
    141 
    142 ### SSH — TCP 22
    143 
    144 ```bash
    145 nmap -sV -p22 \
    146   --script=ssh-hostkey,ssh2-enum-algos <target>
    147 
    148 # Categorized auth/intrusive: run only after reviewing impact
    149 nmap --script-help ssh-auth-methods
    150 nmap -sV -p22 --script=ssh-auth-methods <target>
    151 ```
    152 
    153 ### SMTP — TCP 25/465/587
    154 
    155 ```bash
    156 nmap -sV -p25,465,587 \
    157   --script=smtp-commands,smtp-ntlm-info <target>
    158 
    159 # Open-relay testing can cause delivery attempts: review script/RoE first
    160 nmap --script-help smtp-open-relay
    161 ```
    162 
    163 ### DNS — TCP/UDP 53
    164 
    165 ```bash
    166 sudo nmap -sS -sU -p T:53,U:53 \
    167   --script=dns-nsid,dns-recursion <target>
    168 
    169 # Zone transfer is an explicit follow-up against an authoritative server
    170 nmap -p53 --script=dns-zone-transfer \
    171   --script-args='dns-zone-transfer.domain=example.test' <dns-server>
    172 ```
    173 
    174 ### HTTP — TCP 80/443/8000/8080/8443
    175 
    176 ```bash
    177 nmap -sV -p80,443,8000,8080,8443 \
    178   --script=http-title,http-headers,http-methods <target>
    179 
    180 # More requests and path guessing: useful, but noisier
    181 nmap -sV -p80,443 --script=http-enum <target>
    182 ```
    183 
    184 ### TLS — Any TLS-Wrapped Port
    185 
    186 ```bash
    187 # ssl-enum-ciphers makes many TLS connections and is categorized intrusive
    188 nmap -sV -p443,465,636,993,995,8443 \
    189   --script=ssl-cert,ssl-enum-ciphers,ssl-dh-params <target>
    190 ```
    191 
    192 ### SMB — TCP 445/139
    193 
    194 ```bash
    195 nmap -sV -p139,445 \
    196   --script=smb-protocols,smb2-capabilities,smb2-security-mode,smb2-time,smb-os-discovery \
    197   <target>
    198 
    199 # Share/user enumeration may require credentials and generates audit events
    200 nmap -p445 --script=smb-enum-shares,smb-enum-users <target>
    201 ```
    202 
    203 ### LDAP / Active Directory — TCP 389/636/3268/3269
    204 
    205 ```bash
    206 nmap -sV -p389,636,3268,3269 \
    207   --script=ldap-rootdse,ssl-cert <domain-controller>
    208 
    209 # ldap-search can return substantial directory data; inspect arguments first
    210 nmap --script-help ldap-search
    211 ```
    212 
    213 ### SNMP — UDP 161
    214 
    215 ```bash
    216 sudo nmap -sU -sV -p161 \
    217   --script=snmp-info,snmp-sysdescr,snmp-interfaces \
    218   --script-args='creds.snmp=:public' <target>
    219 ```
    220 
    221 ### RPC / NFS — TCP/UDP 111 and TCP/UDP 2049
    222 
    223 ```bash
    224 sudo nmap -sS -sU -sV -p T:111,2049,U:111,2049 \
    225   --script=rpcinfo,nfs-showmount,nfs-ls,nfs-statfs <target>
    226 ```
    227 
    228 ### Databases and Data Stores
    229 
    230 ```bash
    231 # MySQL
    232 nmap -sV -p3306 --script=mysql-info <target>
    233 
    234 # Categorized auth/intrusive: explicit empty-password check
    235 nmap --script-help mysql-empty-password
    236 nmap -sV -p3306 --script=mysql-empty-password <target>
    237 
    238 # Microsoft SQL Server
    239 nmap -sV -p1433 --script=ms-sql-info,ms-sql-ntlm-info <target>
    240 
    241 # MongoDB
    242 nmap -sV -p27017 --script=mongodb-info,mongodb-databases <target>
    243 
    244 # Redis
    245 nmap -sV -p6379 --script=redis-info <target>
    246 ```
    247 
    248 ### Remote Desktop and VNC
    249 
    250 ```bash
    251 nmap -sV -p3389 --script=rdp-enum-encryption,rdp-ntlm-info <target>
    252 nmap -sV -p5900-5905 --script=vnc-info <target>
    253 ```
    254 
    255 ### Docker API
    256 
    257 ```bash
    258 nmap -sV -p2375,2376 --script=docker-version,ssl-cert <target>
    259 ```
    260 
    261 ---
    262 
    263 ## Broadcast and Prerule Discovery
    264 
    265 ```bash
    266 # Local-segment discovery; many broadcast scripts do not need a target
    267 sudo nmap --script=broadcast-dhcp-discover
    268 sudo nmap --script=broadcast-dns-service-discovery
    269 sudo nmap --script=broadcast-upnp-info
    270 
    271 # Allow a script to add discovered addresses to Nmap's scan queue
    272 sudo nmap --script=broadcast-dns-service-discovery \
    273   --script-args=newtargets
    274 ```
    275 
    276 > [!warning]+ `newtargets` Can Expand Scope
    277 > Broadcast/multicast replies may reveal systems not present in the original target list. Do not enable `newtargets` unless the resulting local segment is explicitly authorized.
    278 
    279 ---
    280 
    281 ## Why a Script Did Not Run or Returned Nothing
    282 
    283 | Symptom | Explanation | Next Step |
    284 |---|---|---|
    285 | No script output | Many scripts return nothing when no finding exists | Add `-d`; inspect `--script-trace` only if needed |
    286 | Script skipped | Port/service did not match its rule | Add `-sV`; verify port; consider `+script` only after review |
    287 | Wrong HTTP site | Name-based virtual hosting | Supply the documented `http.host` argument or scan the hostname |
    288 | TLS certificate differs | SNI/load balancer routing | Scan the hostname and review the script's TLS/SNI arguments |
    289 | Script hangs | Service throttling, filtering, or script bug | Add `--script-timeout`; run one script at a time; use `--script-trace` |
    290 | `SCRIPT ENGINE` error | Missing library, stale database, or incompatible third-party script | Run `nmap --script-updatedb`; inspect debug output and script source |
    291 | Auth script fails | Wrong domain/auth scheme or lockout policy | Stop repeated attempts; validate one credential manually and review RoE |
    292 | UDP script skipped | Port stayed `open|filtered` or version unresolved | Add `-sU -sV`; target the exact UDP port |
    293 
    294 ```bash
    295 # Minimal debugging pattern
    296 nmap -Pn -n -sV -p443 \
    297   --script=ssl-cert --script-timeout 30s -d2 <target>
    298 
    299 # Packet-level script view; keep the port/script set tiny
    300 nmap -Pn -n -p443 --script=ssl-cert --script-trace <target>
    301 ```
    302 
    303 ---
    304 
    305 ## Local Script Discovery and Maintenance
    306 
    307 ```bash
    308 # Installed scripts on this Arch/Omarchy system
    309 find /usr/share/nmap/scripts -maxdepth 1 -type f -name '*.nse' | sort
    310 
    311 # Search by protocol or technique
    312 rg -l 'categories.*vuln' /usr/share/nmap/scripts
    313 rg -l 'SMB|smb' /usr/share/nmap/scripts
    314 
    315 # Rebuild the index after adding or removing a trusted script
    316 sudo nmap --script-updatedb
    317 ```
    318 
    319 > [!danger]+ Third-Party Script Review Checklist
    320 > 1. Read the complete `.nse` file and every non-standard library it loads.
    321 > 2. Check categories, `prerule`/`hostrule`/`portrule`, and the `action` function.
    322 > 3. Look for file writes, `os.execute`, external network calls, credential handling, and exploit/DoS behaviour.
    323 > 4. Pin the source/commit in engagement notes; do not silently replace evidence tooling mid-assessment.
    324 > 5. Test against a lab clone before production-like systems.
    325 
    326 ---
    327 
    328 ## Quick Reference Card
    329 
    330 ```bash
    331 nmap -sV -sC <target>                         # curated defaults
    332 nmap --script-help '<expression>'             # review without scanning
    333 nmap -sV --script='default or safe' <target>  # broader low-impact pass
    334 nmap --script='<name1>,<name2>' <target>      # explicit bundle
    335 nmap --script='http-*' -p80,443 <target>      # quoted wildcard
    336 nmap --script-args='key=value' <target>       # inline argument
    337 nmap --script-args-file args.txt <target>     # argument file
    338 nmap --script-timeout 30s --script=...        # per-script ceiling
    339 nmap --script-trace --script=...              # script traffic debug
    340 sudo nmap --script-updatedb                    # rebuild local script index
    341 ```
    342 
    343 ---
    344 
    345 ## References
    346 
    347 1. [Nmap NSE Usage and Examples](https://nmap.org/book/nse-usage.html)
    348 2. [Nmap Scripting Engine Reference](https://nmap.org/book/man-nse.html)
    349 3. [NSE Documentation Portal](https://nmap.org/nsedoc/)
    350 4. [NSE Script Format](https://nmap.org/book/nse-script-format.html)
    351 5. NSE Guide — comprehensive vault reference