nmap-nse-scripts.md (13299B)
1 --- 2 title: "Nmap NSE Scripts (2026)" 3 description: "Operator quick reference for selecting, running, constraining and troubleshooting Nmap NSE scripts by category and target service." 4 category: enumeration 5 tags: ["enumeration", "port-scanning", "network"] 6 tools: ["Nmap"] 7 difficulty: intermediate 8 updated: "2026-08-28" 9 source: "vault:Enumeration/Nmap NSE Scripts Cheatsheet 2026.md" 10 --- 11 > [!important]+ Purpose 12 > This is the compact, action-first NSE sheet: how to select, review, run, constrain, and troubleshoot scripts during an authorized assessment. For detailed per-port write-ups and example output, use NSE Guide. Pair with Nmap Cheatsheet 2026 and Common Ports and Services Cheatsheet 2026. 13 14 > [!danger]+ NSE Executes Code 15 > NSE scripts are Lua programs and are **not sandboxed**. Category labels describe intent; they are not a guarantee of safety. Audit third-party scripts and review `--script-help` before using `intrusive`, `brute`, `vuln`, `exploit`, `dos`, or `fuzzer` against anything sensitive. 16 17 --- 18 19 ## The 60-Second Workflow 20 21 ```bash 22 # 1. Find the service and version first 23 nmap -Pn -n -sV -p443 <target> 24 25 # 2. Inspect candidate scripts before executing them 26 nmap --script-help 'http-title,ssl-cert,ssl-enum-ciphers' 27 28 # 3. Run an explicit, reviewable bundle and save evidence 29 nmap -Pn -n -sV -p443 \ 30 --script=http-title,http-headers,ssl-cert,ssl-enum-ciphers \ 31 <target> -oA nse-https 32 33 # 4. Trace only when output is missing or surprising 34 nmap -Pn -n -p443 --script=ssl-cert --script-trace <target> 35 ``` 36 37 > [!tip]+ Explicit Names Beat Giant Categories 38 > `--script=vuln` is easy to type but difficult to review and reproduce. A comma-separated list records exactly what was approved and run. Use categories for discovery, then narrow the final evidence command to named scripts. 39 40 --- 41 42 ## Selection Syntax 43 44 | Syntax | Meaning | 45 |---|---| 46 | `-sC` | Run the curated `default` category | 47 | `--script=default` | Same script selection as `-sC` | 48 | `--script=http-title` | One named script | 49 | `--script=http-title,ssl-cert` | Multiple names/categories (logical OR) | 50 | `--script='http-*'` | All matching script names; quote the shell wildcard | 51 | `--script='default or safe'` | Scripts in either category | 52 | `--script='default and safe'` | Scripts present in both categories | 53 | `--script='(default or safe) and not broadcast'` | Boolean selection with exclusion | 54 | `--script='+http-title'` | Force a script even if its run rule would not select the port | 55 | `--script=/path/check.nse` | Run a trusted script by file path | 56 | `--script-help <expression>` | Show names, categories, and descriptions without scanning | 57 58 > [!warning]+ The `+` Prefix Bypasses a Safety Check 59 > A script's `portrule`/`hostrule` normally decides whether it applies. Forcing execution is useful on non-standard ports, but first add `-sV` and verify the detected service. Do not use `+` merely because a script produced no output. 60 61 --- 62 63 ## Script Categories by Operational Risk 64 65 | Category | Typical Purpose | Starting Assumption | 66 |---|---|---| 67 | `default` | Curated useful/fast/reliable checks | Usually a reasonable first pass | 68 | `safe` | Intended not to exploit, crash, or consume excessive resources | Low impact, not zero traffic | 69 | `version` | Enhances service/version detection | Usually low impact | 70 | `discovery` | Finds hosts, services, names, or configuration | Review scope expansion and query volume | 71 | `broadcast` | Local multicast/broadcast discovery | Can discover targets outside the original list | 72 | `auth` | Authentication configuration or bypass checks | May generate login/security events | 73 | `external` | Sends information to an external service | Privacy/data-handling review required | 74 | `vuln` | Tests for known vulnerabilities | Mixed; read each script description | 75 | `intrusive` | Higher traffic, state changes, or resource use possible | Explicit approval and maintenance awareness | 76 | `brute` | Repeated credential attempts | Lockout, alerting, and audit-log risk | 77 | `exploit` | Attempts exploitation | High risk; explicit RoE | 78 | `dos` | Tests denial-of-service conditions | Never run casually against live services | 79 | `fuzzer` | Sends malformed/unexpected inputs | Crash/state-corruption risk | 80 | `malware` | Detects malware/backdoors | Read implementation; behaviour varies | 81 82 ```bash 83 # Review everything selected by an expression without touching a target 84 nmap --script-help '(default or safe) and not external' 85 86 # Controlled low-impact starting point 87 nmap -sV --script='default or safe' <target> 88 ``` 89 90 --- 91 92 ## Script Arguments 93 94 ```bash 95 # Inline comma-separated key/value pairs: quote the whole expression 96 nmap -p80 --script=http-title \ 97 --script-args='http.host=app.example.test' <target> 98 99 # SMB authentication 100 nmap -p445 --script=smb-enum-shares \ 101 --script-args='smbdomain=ACME,smbusername=alice,smbpassword=Password123!' \ 102 <target> 103 104 # SNMP community supplied as an empty username plus password/community 105 sudo nmap -sU -p161 --script=snmp-info,snmp-sysdescr \ 106 --script-args='creds.snmp=:public' <target> 107 108 # Prefer a file when values need complex quoting or should not sit in history 109 nmap -p445 --script=smb-enum-shares \ 110 --script-args-file nse-args.txt <target> 111 ``` 112 113 > [!warning]+ Credential Handling 114 > Command-line secrets may appear in shell history and process listings. Use dedicated assessment credentials, protect argument files, remove them according to the evidence-handling plan, and prefer Kerberos/ticket workflows where the script supports them. 115 116 ### Useful Global Controls 117 118 | Option | Purpose | 119 |---|---| 120 | `--script-args='k=v,...'` | Supply script arguments inline | 121 | `--script-args-file file` | Load arguments from a file | 122 | `--script-timeout 30s` | Stop an individual script after the limit | 123 | `--script-trace` | Show data sent and received by scripts | 124 | `--script-help expression` | Review matching script documentation | 125 | `--script-updatedb` | Rebuild `script.db` after adding/removing scripts | 126 | `-d` / `-d2` | Add Nmap/NSE debug information | 127 | `-oA basename` | Save normal, XML, and greppable evidence | 128 129 --- 130 131 ## Protocol Bundles — Review Before Use 132 133 > [!note]+ Adjust Ports to the Detected Service 134 > The ports below are defaults, not requirements. Run `-sV`, then target the actual service wherever it is listening. Most examples favor `safe`/`discovery` scripts, but specifically marked follow-ups include `auth` or `intrusive` scripts. 135 136 ### FTP — TCP 21 137 138 ```bash 139 nmap -sV -p21 --script=ftp-anon,ftp-syst,ftp-bounce <target> 140 ``` 141 142 ### SSH — TCP 22 143 144 ```bash 145 nmap -sV -p22 \ 146 --script=ssh-hostkey,ssh2-enum-algos <target> 147 148 # Categorized auth/intrusive: run only after reviewing impact 149 nmap --script-help ssh-auth-methods 150 nmap -sV -p22 --script=ssh-auth-methods <target> 151 ``` 152 153 ### SMTP — TCP 25/465/587 154 155 ```bash 156 nmap -sV -p25,465,587 \ 157 --script=smtp-commands,smtp-ntlm-info <target> 158 159 # Open-relay testing can cause delivery attempts: review script/RoE first 160 nmap --script-help smtp-open-relay 161 ``` 162 163 ### DNS — TCP/UDP 53 164 165 ```bash 166 sudo nmap -sS -sU -p T:53,U:53 \ 167 --script=dns-nsid,dns-recursion <target> 168 169 # Zone transfer is an explicit follow-up against an authoritative server 170 nmap -p53 --script=dns-zone-transfer \ 171 --script-args='dns-zone-transfer.domain=example.test' <dns-server> 172 ``` 173 174 ### HTTP — TCP 80/443/8000/8080/8443 175 176 ```bash 177 nmap -sV -p80,443,8000,8080,8443 \ 178 --script=http-title,http-headers,http-methods <target> 179 180 # More requests and path guessing: useful, but noisier 181 nmap -sV -p80,443 --script=http-enum <target> 182 ``` 183 184 ### TLS — Any TLS-Wrapped Port 185 186 ```bash 187 # ssl-enum-ciphers makes many TLS connections and is categorized intrusive 188 nmap -sV -p443,465,636,993,995,8443 \ 189 --script=ssl-cert,ssl-enum-ciphers,ssl-dh-params <target> 190 ``` 191 192 ### SMB — TCP 445/139 193 194 ```bash 195 nmap -sV -p139,445 \ 196 --script=smb-protocols,smb2-capabilities,smb2-security-mode,smb2-time,smb-os-discovery \ 197 <target> 198 199 # Share/user enumeration may require credentials and generates audit events 200 nmap -p445 --script=smb-enum-shares,smb-enum-users <target> 201 ``` 202 203 ### LDAP / Active Directory — TCP 389/636/3268/3269 204 205 ```bash 206 nmap -sV -p389,636,3268,3269 \ 207 --script=ldap-rootdse,ssl-cert <domain-controller> 208 209 # ldap-search can return substantial directory data; inspect arguments first 210 nmap --script-help ldap-search 211 ``` 212 213 ### SNMP — UDP 161 214 215 ```bash 216 sudo nmap -sU -sV -p161 \ 217 --script=snmp-info,snmp-sysdescr,snmp-interfaces \ 218 --script-args='creds.snmp=:public' <target> 219 ``` 220 221 ### RPC / NFS — TCP/UDP 111 and TCP/UDP 2049 222 223 ```bash 224 sudo nmap -sS -sU -sV -p T:111,2049,U:111,2049 \ 225 --script=rpcinfo,nfs-showmount,nfs-ls,nfs-statfs <target> 226 ``` 227 228 ### Databases and Data Stores 229 230 ```bash 231 # MySQL 232 nmap -sV -p3306 --script=mysql-info <target> 233 234 # Categorized auth/intrusive: explicit empty-password check 235 nmap --script-help mysql-empty-password 236 nmap -sV -p3306 --script=mysql-empty-password <target> 237 238 # Microsoft SQL Server 239 nmap -sV -p1433 --script=ms-sql-info,ms-sql-ntlm-info <target> 240 241 # MongoDB 242 nmap -sV -p27017 --script=mongodb-info,mongodb-databases <target> 243 244 # Redis 245 nmap -sV -p6379 --script=redis-info <target> 246 ``` 247 248 ### Remote Desktop and VNC 249 250 ```bash 251 nmap -sV -p3389 --script=rdp-enum-encryption,rdp-ntlm-info <target> 252 nmap -sV -p5900-5905 --script=vnc-info <target> 253 ``` 254 255 ### Docker API 256 257 ```bash 258 nmap -sV -p2375,2376 --script=docker-version,ssl-cert <target> 259 ``` 260 261 --- 262 263 ## Broadcast and Prerule Discovery 264 265 ```bash 266 # Local-segment discovery; many broadcast scripts do not need a target 267 sudo nmap --script=broadcast-dhcp-discover 268 sudo nmap --script=broadcast-dns-service-discovery 269 sudo nmap --script=broadcast-upnp-info 270 271 # Allow a script to add discovered addresses to Nmap's scan queue 272 sudo nmap --script=broadcast-dns-service-discovery \ 273 --script-args=newtargets 274 ``` 275 276 > [!warning]+ `newtargets` Can Expand Scope 277 > Broadcast/multicast replies may reveal systems not present in the original target list. Do not enable `newtargets` unless the resulting local segment is explicitly authorized. 278 279 --- 280 281 ## Why a Script Did Not Run or Returned Nothing 282 283 | Symptom | Explanation | Next Step | 284 |---|---|---| 285 | No script output | Many scripts return nothing when no finding exists | Add `-d`; inspect `--script-trace` only if needed | 286 | Script skipped | Port/service did not match its rule | Add `-sV`; verify port; consider `+script` only after review | 287 | Wrong HTTP site | Name-based virtual hosting | Supply the documented `http.host` argument or scan the hostname | 288 | TLS certificate differs | SNI/load balancer routing | Scan the hostname and review the script's TLS/SNI arguments | 289 | Script hangs | Service throttling, filtering, or script bug | Add `--script-timeout`; run one script at a time; use `--script-trace` | 290 | `SCRIPT ENGINE` error | Missing library, stale database, or incompatible third-party script | Run `nmap --script-updatedb`; inspect debug output and script source | 291 | Auth script fails | Wrong domain/auth scheme or lockout policy | Stop repeated attempts; validate one credential manually and review RoE | 292 | UDP script skipped | Port stayed `open|filtered` or version unresolved | Add `-sU -sV`; target the exact UDP port | 293 294 ```bash 295 # Minimal debugging pattern 296 nmap -Pn -n -sV -p443 \ 297 --script=ssl-cert --script-timeout 30s -d2 <target> 298 299 # Packet-level script view; keep the port/script set tiny 300 nmap -Pn -n -p443 --script=ssl-cert --script-trace <target> 301 ``` 302 303 --- 304 305 ## Local Script Discovery and Maintenance 306 307 ```bash 308 # Installed scripts on this Arch/Omarchy system 309 find /usr/share/nmap/scripts -maxdepth 1 -type f -name '*.nse' | sort 310 311 # Search by protocol or technique 312 rg -l 'categories.*vuln' /usr/share/nmap/scripts 313 rg -l 'SMB|smb' /usr/share/nmap/scripts 314 315 # Rebuild the index after adding or removing a trusted script 316 sudo nmap --script-updatedb 317 ``` 318 319 > [!danger]+ Third-Party Script Review Checklist 320 > 1. Read the complete `.nse` file and every non-standard library it loads. 321 > 2. Check categories, `prerule`/`hostrule`/`portrule`, and the `action` function. 322 > 3. Look for file writes, `os.execute`, external network calls, credential handling, and exploit/DoS behaviour. 323 > 4. Pin the source/commit in engagement notes; do not silently replace evidence tooling mid-assessment. 324 > 5. Test against a lab clone before production-like systems. 325 326 --- 327 328 ## Quick Reference Card 329 330 ```bash 331 nmap -sV -sC <target> # curated defaults 332 nmap --script-help '<expression>' # review without scanning 333 nmap -sV --script='default or safe' <target> # broader low-impact pass 334 nmap --script='<name1>,<name2>' <target> # explicit bundle 335 nmap --script='http-*' -p80,443 <target> # quoted wildcard 336 nmap --script-args='key=value' <target> # inline argument 337 nmap --script-args-file args.txt <target> # argument file 338 nmap --script-timeout 30s --script=... # per-script ceiling 339 nmap --script-trace --script=... # script traffic debug 340 sudo nmap --script-updatedb # rebuild local script index 341 ``` 342 343 --- 344 345 ## References 346 347 1. [Nmap NSE Usage and Examples](https://nmap.org/book/nse-usage.html) 348 2. [Nmap Scripting Engine Reference](https://nmap.org/book/man-nse.html) 349 3. [NSE Documentation Portal](https://nmap.org/nsedoc/) 350 4. [NSE Script Format](https://nmap.org/book/nse-script-format.html) 351 5. NSE Guide — comprehensive vault reference