nmap.md (17068B)
1 --- 2 title: "Nmap" 3 description: "Nmap host discovery, port/service/version scanning, timing, output formats and common scan recipes." 4 category: enumeration 5 tags: [enumeration, port-scanning, network] 6 tools: [Nmap] 7 difficulty: beginner 8 updated: "2026-08-09" 9 source: "vault:Enumeration/Nmap Cheatsheet 2026.md" 10 --- 11 12 # Nmap 13 14 > **Important — Why This Sheet Exists.** Most people stop at `nmap -sC -sV -oA scan <target>`. That's maybe 20% of what Nmap can actually do. This sheet covers the flags, workflows, and interactive tricks that rarely show up in beginner guides — the stuff that separates "ran a scan" from "understood the target and its defences." Pairs with Awesome NMAP grep (post-processing greppable output) and the NSE Guide (script-level enumeration per port). 15 16 --- 17 18 ## Live Runtime Control 19 20 > **Tip — Interactive Keys While a Scan Is Running.** Nmap has a **runtime keyboard interface** — you don't need `--stats-every` or a second terminal to check progress on a long `-p-` scan. 21 > 1. Press **`v`** — increase verbosity live, mid-scan 22 > 2. Press **`V`** — decrease verbosity 23 > 3. Press **`d`** — increase debug level live 24 > 4. Press **`D`** — decrease debug level 25 > 5. Press **any other key** (e.g. spacebar) — print an immediate status line: % complete, ETA, current probe 26 > 27 > No flag needed — it works on any running scan in an interactive terminal. Combine with `--stats-every 10s` to also get automatic periodic updates without touching the keyboard. 28 29 ```bash 30 nmap -p- -T4 --stats-every 15s 10.10.10.5 31 # Then just tap spacebar anytime to force an immediate progress line 32 ``` 33 34 --- 35 36 ## Precision Timing — Beyond `-T0`–`-T5` 37 38 > **Important — `-T` Is a Preset, Not a Real Setting.** `-T0`–`-T5` are just bundles of the real underlying timing flags below. Most people never touch the real knobs — but that's where actual control lives. 39 40 | Flag | Controls | Why It Matters | 41 |---|---|---| 42 | `--min-rate <num>` | Minimum packets sent per second | Forces a floor speed — use to stop Nmap self-throttling on a fast link | 43 | `--max-rate <num>` | Maximum packets sent per second | Hard ceiling — essential for not knocking over fragile embedded/IoT/ICS devices | 44 | `--min-rtt-timeout` / `--max-rtt-timeout` / `--initial-rtt-timeout` | RTT probe timeout bounds | Tune for high-latency links (VPN pivots, satellite, Tor) instead of accepting false "filtered" results | 45 | `--host-timeout <time>` | Skip a host entirely after this long | Stops one dead/firewalled host from eating your whole scan window | 46 | `--scan-delay` / `--max-scan-delay` | Forced delay between probes | Real stealth — evades simple rate-based IDS thresholds far better than `-T1` alone | 47 | `--min-parallelism` / `--max-parallelism` | Probes in flight simultaneously | Fine-grained alternative to timing templates on congested or lossy networks | 48 49 ```bash 50 # Fast internal network, but don't crash the one flaky IoT device on it 51 sudo nmap -p- --min-rate 2000 --max-rate 5000 --host-timeout 5m 10.0.0.0/24 52 53 # Scanning over a slow VPN pivot — stop false "filtered" results from RTT timeouts 54 sudo nmap -sS --initial-rtt-timeout 500ms --max-rtt-timeout 4s -p 1-1000 172.16.5.10 55 ``` 56 57 > **Tip — The Rate-Limit Bypass Almost Nobody Uses.** Many Linux hosts and firewalls **rate-limit RST/ICMP unreachable responses** — this makes closed/filtered ports look identical and skews your results without you realising it. 58 > ```bash 59 > sudo nmap -sS --defeat-rst-ratelimit -p- 10.10.10.5 60 > sudo nmap -sU --defeat-icmp-ratelimit --top-ports 200 10.10.10.5 61 > ``` 62 > 1. **`--defeat-rst-ratelimit`** — keeps probing past a detected RST rate limit instead of assuming "filtered" 63 > 2. **`--defeat-icmp-ratelimit`** — same idea for UDP scans relying on ICMP port-unreachable 64 > 3. Without these, a rate-limited Linux target can make an open UDP port look closed/filtered — a classic source of false negatives 65 66 --- 67 68 ## Firewall & IDS Evasion 69 70 > **Danger — Authorisation Required.** Every technique below changes how your traffic looks to defensive tooling. Only use these within signed RoE scope — evasion outside authorised engagements is a fast way to turn a pentest into a criminal case. 71 72 ### Non-Standard Scan Types (Exploit RFC 793 Gaps) 73 74 | Flag | Scan Type | Why It Evades Simple Filters | 75 |---|---|---| 76 | `-sN` | NULL scan (no flags set) | Many stateless ACLs only match SYN/ACK patterns — a flagless packet slips through unnoticed | 77 | `-sF` | FIN scan | Same idea — closed ports RST, open/filtered stay silent, and it isn't a "connection attempt" to naive logging | 78 | `-sX` | Xmas scan (FIN+PSH+URG set) | "Lights up like a Christmas tree" — again exploits RFC 793 behaviour most firewalls never account for | 79 | `-sA` | ACK scan | Doesn't determine open/closed — determines **filtered vs unfiltered**, i.e. maps firewall rule sets directly | 80 | `-sW` | Window scan | Variant of ACK scan using TCP window size quirks to infer open ports on some stacks | 81 | `-sM` | Maimon scan | FIN/ACK combo — exploits certain BSD-derived stack behaviour | 82 | `-sY` / `-sZ` | SCTP INIT / COOKIE-ECHO scan | Almost nobody scans [SCTP](https://en.wikipedia.org/wiki/Stream_Control_Transmission_Protocol) — telecom/signalling and some VoIP infra runs on it and is rarely monitored | 83 | `-sO` | IP protocol scan | Finds *which protocols* (not ports) a host speaks — reveals hidden GRE tunnels, ESP/IPsec, OSPF | 84 85 > **Warning — These Scan Types Need Root and Have Blind Spots.** 86 > 1. All of `-sN`/`-sF`/`-sX`/`-sM` **require raw socket access** (root/sudo) and only work reliably against Unix-like TCP stacks per RFC 793 — Windows targets typically respond with RST to everything, making results useless there 87 > 2. These scans **cannot distinguish "open" from "filtered"** — silence means either. Confirm with a normal `-sS` or targeted service probe afterward 88 89 ### Packet Manipulation 90 91 ```bash 92 # Fragment packets — splits the TCP header across multiple IP fragments 93 sudo nmap -f 10.10.10.5 # 8-byte fragments 94 sudo nmap -ff 10.10.10.5 # 16-byte fragments (double fragmentation) 95 sudo nmap --mtu 24 10.10.10.5 # custom fragment size (must be multiple of 8) 96 97 # Pad probes with junk data to break simple length-based IDS signatures 98 sudo nmap --data-length 25 -p 80,443 10.10.10.5 99 100 # Set a custom TTL to blend in with expected regional/hop-count profiles 101 sudo nmap --ttl 128 10.10.10.5 102 103 # Spoof or randomise your MAC address on local segments 104 sudo nmap --spoof-mac 00:11:22:33:44:55 -e eth0 10.10.10.5 105 sudo nmap --spoof-mac Apple -e eth0 10.10.10.5 # vendor-prefix randomisation 106 sudo nmap --spoof-mac 0 -e eth0 10.10.10.5 # fully random MAC 107 108 # Bad checksum probe — see how the firewall/IDS reacts to intentionally invalid packets 109 sudo nmap --badsum 10.10.10.5 110 ``` 111 112 > **Info — Command Breakdown.** 113 > 1. **`-f` / `-ff` / `--mtu`** — fragmentation defeats older/simple IDS that fail to reassemble packets before signature matching; modern IDS mostly handles this correctly now, but it's a zero-cost addition to an evasion profile 114 > 2. **`--data-length`** — randomises payload size so probes don't match a fixed-length scan signature 115 > 3. **`--spoof-mac`** — useful on internal segments where MAC-based NAC/allowlisting exists, or simply to avoid leaving your real NIC vendor fingerprint in switch logs 116 > 4. **`--badsum`** — a genuine target silently drops these; a host that *does* respond may indicate a security device doing packet processing in a naive way 117 118 ### Decoys and Source Manipulation 119 120 ```bash 121 # Hide your real scan among decoy source IPs 122 sudo nmap -D RND:10 10.10.10.5 123 sudo nmap -D decoy1.com,decoy2.com,ME,decoy3.com 10.10.10.5 124 125 # Scan from a "trusted" source port — some legacy firewalls allow traffic FROM port 53/20/88 126 sudo nmap --source-port 53 -p- 10.10.10.5 127 sudo nmap -g 88 -p 1-1000 10.10.10.5 128 129 # Force a specific egress interface on a multi-homed attack box (common on pivots) 130 sudo nmap -e tun0 10.10.10.5 131 ``` 132 133 > **Warning — Decoys Are Weaker Than They Used to Be.** 134 > 1. Modern IDS/SIEM correlates **behaviour and timing patterns**, not just source-IP counts — decoys mainly slow down manual log review now, not automated detection 135 > 2. Decoy IPs must actually be **up and reachable**, or the target's SYN-ACKs to them generate RSTs that can reveal which "decoy" is fake 136 > 3. `--source-port` only works against firewalls with genuinely naive "allow if source port = X" rules — increasingly rare but still found on legacy/embedded gear 137 138 --- 139 140 ## Idle (Zombie) Scanning 141 142 > **Important — How Idle Scan Actually Works.** [Idle scanning (`-sI`)](https://nmap.org/book/idlescan.html) spoofs your source IP as a third-party "zombie" host, then infers port state purely by watching the **zombie's IP ID sequence** increment. The target only ever sees traffic from the zombie — never from you. 143 > 1. Find a zombie: an idle host with a **predictable, incrementing global IPID sequence** (old printers, embedded devices, unpatched legacy boxes are common candidates) 144 > 2. Nmap's own `ipidseq` NSE script screens hosts for IPID predictability 145 146 ```bash 147 # Step 1: Find a usable zombie on the network 148 nmap -p80 --script ipidseq 192.168.1.0/24 149 150 # Step 2: Run the idle scan through the identified zombie 151 sudo nmap -sI 192.168.1.50 -p- 10.10.10.5 152 ``` 153 154 > **Success — When This Is Worth the Setup Effort.** 155 > 1. Fully deniable scanning — logs on the actual target show the **zombie's** IP, never yours 156 > 2. Useful for mapping firewall rules from a "trusted internal" vantage point without routing through it directly 157 > 3. Slow and fragile — busy or NAT'd zombies break the technique; treat it as a specialty tool, not a default workflow 158 159 --- 160 161 ## Host Discovery Tricks Beyond a Basic Ping 162 163 > **Info — Custom Discovery Probes.** Default `-sn` ping discovery relies on ICMP echo, which is blocked by almost every modern firewall. These flags let you build a discovery probe firewalls don't expect: 164 165 ```bash 166 # TCP SYN discovery to specific "probably open" ports instead of ICMP 167 sudo nmap -sn -PS22,80,443,3389 10.10.10.0/24 168 169 # TCP ACK discovery — some stateless firewalls pass ACK packets through 170 sudo nmap -sn -PA80,443 10.10.10.0/24 171 172 # UDP discovery probe (DNS/NTP/SNMP ports often get a response even when ICMP is dead) 173 sudo nmap -sn -PU53,161 10.10.10.0/24 174 175 # SCTP INIT discovery 176 sudo nmap -sn -PY 10.10.10.0/24 177 178 # ICMP variants beyond plain echo 179 sudo nmap -sn -PE -PP -PM 10.10.10.0/24 # echo, timestamp, netmask requests 180 181 # IP protocol ping — useful when ICMP/TCP/UDP are all filtered but other IP protocols aren't 182 sudo nmap -sn -PO 10.10.10.0/24 183 184 # Skip ARP ping on local segments (ARP is usually more reliable, but sometimes you want raw IP-layer behaviour) 185 sudo nmap -sn --disable-arp-ping 10.10.10.0/24 186 187 # Resolve names via a specific DNS server instead of the system resolver 188 nmap --dns-servers 8.8.8.8,1.1.1.1 -sn 10.10.10.0/24 189 190 # Pure target enumeration — resolves/lists targets without sending a single packet to them 191 nmap -sL 10.10.10.0/24 192 ``` 193 194 > **Tip — `-sL` Is a Free Sanity Check.** Run `-sL` first on any new CIDR range before touching it with a real scan — it just does reverse-DNS/target-list resolution with **zero packets sent to the targets themselves**. Perfect for validating a scope file has no typos before you burn scan time on it. 195 196 --- 197 198 ## Scan Resume, Diffing & Continuous Recon 199 200 > **Tip — Resume an Interrupted Scan.** A `-p-` scan against a large range that gets killed (SSH drop, laptop sleep, Ctrl+C) doesn't have to restart from zero: 201 > ```bash 202 > nmap -p- -oA big_scan 10.0.0.0/16 203 > # ...interrupted... 204 > nmap --resume big_scan.nmap 205 > ``` 206 207 > **Example — Diffing Scans Over Time With `ndiff`.** [ndiff](https://nmap.org/ndiff/) ships with Nmap and compares two XML scan results — essential for continuous recon on long engagements or bug bounty monitoring. 208 > ```bash 209 > nmap -oX scan_day1.xml 10.10.10.5 210 > # ...next day... 211 > nmap -oX scan_day2.xml 10.10.10.5 212 > ndiff scan_day1.xml scan_day2.xml 213 > ``` 214 > 1. Highlights newly opened/closed ports, changed service versions, new hosts appearing on a range 215 > 2. Run this on a cron job against in-scope external ranges during a multi-week engagement to catch new attack surface the moment it appears 216 217 ### HTML Reporting 218 219 ```bash 220 nmap -oX scan.xml 10.10.10.5 221 xsltproc scan.xml -o scan_report.html 222 ``` 223 224 > **Info — Command Breakdown.** 225 > 1. Nmap's XML output ships with a built-in XSL stylesheet reference — `xsltproc` (or any XSLT processor) turns it into a **clickable HTML report** with zero extra tooling 226 > 2. Great for handing raw scan evidence to a non-technical stakeholder without teaching them to read `.nmap` text output 227 228 --- 229 230 ## NSE Tricks Beyond `--script=default,vuln` 231 232 > **Info — Debugging and Extending NSE.** 233 > ```bash 234 > # See the raw NSE network traffic a script generates — invaluable when a script "hangs" or gives odd results 235 > nmap --script-trace --script=http-enum -p80 10.10.10.5 236 > 237 > # After adding/editing a custom .nse script, refresh Nmap's script database 238 > nmap --script-updatedb 239 > 240 > # Cross-reference every detected service version against a CVE database directly 241 > nmap -sV --script=vulners 10.10.10.5 242 > ``` 243 > 1. **`--script-trace`** — shows every packet sent/received by the NSE engine; the fastest way to debug "why is this script timing out" 244 > 2. **`vulners`** — turns plain version detection into an instant CVE list with CVSS scores; massively underused compared to the generic `vuln` category 245 246 > **Example — Scripts That Need NO Target At All.** Several NSE scripts operate purely on **broadcast/multicast traffic** on your local segment — no IP argument required: 247 > ```bash 248 > nmap --script broadcast-dhcp-discover 249 > nmap --script broadcast-ping 250 > nmap --script llmnr-resolve --script-args 'newtargets,llmnr-resolve.hostname=printer' 251 > ``` 252 > 1. `broadcast-dhcp-discover` — requests a DHCP lease to reveal DHCP server, gateway, DNS, and lease policy, before you even have an IP configuration 253 > 2. `broadcast-ping` — finds live hosts via broadcast ping where individual host discovery is filtered 254 > 3. This category is a goldmine on internal engagements before you've even set a static IP 255 256 --- 257 258 ## IPv6 and Protocol-Level Recon 259 260 > **Warning — IPv6 Is the Overlooked Attack Surface.** 261 > 1. Enterprise firewalls and monitoring are frequently **tuned only for IPv4** — the same host can have a wide-open IPv6 stack nobody is watching 262 > 2. Always test both stacks explicitly: 263 > ```bash 264 > nmap -6 -sV fe80::1%eth0 265 > nmap -6 -sV 2001:db8::1 266 > ``` 267 > 3. `-sO` (IP protocol scan, shown above) is the easiest way to find **GRE tunnels, IPsec (ESP/AH), OSPF** — infrastructure most port-based scanning never reveals 268 269 --- 270 271 ## Companion Tool: Nping 272 273 > **Info — [Nping](https://nmap.org/nping/) Overview.** Ships with Nmap. Built for crafting arbitrary raw packets — useful when Nmap's own flags don't give enough control. 274 > 1. Custom TCP/UDP/ICMP/ARP packet crafting for testing specific firewall rules in isolation 275 > 2. Can run in `--echo-client`/`--echo-server` mode to test round-trip packet mangling across a path 276 > 3. Good for building a repeatable, minimal test case to hand to a network team ("this exact packet gets dropped here") 277 278 ```bash 279 # Craft a single custom TCP SYN packet to a specific port with custom flags/TTL 280 nping --tcp -p 443 --flags syn --ttl 64 -c 1 10.10.10.5 281 282 # ARP ping a local subnet (faster and more reliable than ICMP on local segments) 283 sudo nping --arp -c 1 10.10.10.0/24 284 ``` 285 286 --- 287 288 ## Quick Reference — Flags Almost Nobody Uses 289 290 | Flag | Purpose | 291 |---|---| 292 | `--stats-every 10s` + spacebar | Live progress without guessing if a scan has hung | 293 | `--defeat-rst-ratelimit` / `--defeat-icmp-ratelimit` | Fix false "filtered" results from rate-limited targets | 294 | `--host-timeout` | Don't let one dead host stall an entire range scan | 295 | `-sO` | Find protocols (GRE/ESP/OSPF), not just ports | 296 | `-sI` + `ipidseq` | Fully deniable scanning via a zombie host | 297 | `-sL` | Zero-packet scope/target-list sanity check | 298 | `--resume` | Never lose progress on a killed `-p-` scan again | 299 | `ndiff` | Detect new attack surface across long engagements automatically | 300 | `--script-trace` | Debug NSE scripts that hang or misbehave | 301 | `--script=vulners` | Instant CVE/CVSS mapping from version detection | 302 | `broadcast-*` NSE scripts | Enumerate before you even have an IP address | 303 | `-6` | Test the IPv6 stack nobody else is monitoring | 304 | `nping` | Craft the one exact packet you need when Nmap's flags aren't granular enough | 305 306 --- 307 308 ## References 309 310 1. [Nmap Reference Guide](https://nmap.org/book/man.html) 311 2. [Nmap — Idle Scan (-sI) Documentation](https://nmap.org/book/idlescan.html) 312 3. [Nmap — Firewall/IDS Evasion and Spoofing](https://nmap.org/book/man-bypass-firewalls-ids.html) 313 4. [ndiff — Nmap Scan Comparison Tool](https://nmap.org/ndiff/) 314 5. [Nping Reference Guide](https://nmap.org/nping/) 315 6. [NSE Documentation Portal](https://nmap.org/nsedoc/) 316 7. [Vulners NSE Script](https://nmap.org/nsedoc/scripts/vulners.html)