daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nmap.md (17068B)


      1 ---
      2 title: "Nmap"
      3 description: "Nmap host discovery, port/service/version scanning, timing, output formats and common scan recipes."
      4 category: enumeration
      5 tags: [enumeration, port-scanning, network]
      6 tools: [Nmap]
      7 difficulty: beginner
      8 updated: "2026-08-09"
      9 source: "vault:Enumeration/Nmap Cheatsheet 2026.md"
     10 ---
     11 
     12 # Nmap
     13 
     14 > **Important — Why This Sheet Exists.** Most people stop at `nmap -sC -sV -oA scan <target>`. That's maybe 20% of what Nmap can actually do. This sheet covers the flags, workflows, and interactive tricks that rarely show up in beginner guides — the stuff that separates "ran a scan" from "understood the target and its defences." Pairs with Awesome NMAP grep (post-processing greppable output) and the NSE Guide (script-level enumeration per port).
     15 
     16 ---
     17 
     18 ## Live Runtime Control
     19 
     20 > **Tip — Interactive Keys While a Scan Is Running.** Nmap has a **runtime keyboard interface** — you don't need `--stats-every` or a second terminal to check progress on a long `-p-` scan.
     21 > 1. Press **`v`** — increase verbosity live, mid-scan
     22 > 2. Press **`V`** — decrease verbosity
     23 > 3. Press **`d`** — increase debug level live
     24 > 4. Press **`D`** — decrease debug level
     25 > 5. Press **any other key** (e.g. spacebar) — print an immediate status line: % complete, ETA, current probe
     26 >
     27 > No flag needed — it works on any running scan in an interactive terminal. Combine with `--stats-every 10s` to also get automatic periodic updates without touching the keyboard.
     28 
     29 ```bash
     30 nmap -p- -T4 --stats-every 15s 10.10.10.5
     31 # Then just tap spacebar anytime to force an immediate progress line
     32 ```
     33 
     34 ---
     35 
     36 ## Precision Timing — Beyond `-T0`–`-T5`
     37 
     38 > **Important — `-T` Is a Preset, Not a Real Setting.** `-T0`–`-T5` are just bundles of the real underlying timing flags below. Most people never touch the real knobs — but that's where actual control lives.
     39 
     40 | Flag | Controls | Why It Matters |
     41 |---|---|---|
     42 | `--min-rate <num>` | Minimum packets sent per second | Forces a floor speed — use to stop Nmap self-throttling on a fast link |
     43 | `--max-rate <num>` | Maximum packets sent per second | Hard ceiling — essential for not knocking over fragile embedded/IoT/ICS devices |
     44 | `--min-rtt-timeout` / `--max-rtt-timeout` / `--initial-rtt-timeout` | RTT probe timeout bounds | Tune for high-latency links (VPN pivots, satellite, Tor) instead of accepting false "filtered" results |
     45 | `--host-timeout <time>` | Skip a host entirely after this long | Stops one dead/firewalled host from eating your whole scan window |
     46 | `--scan-delay` / `--max-scan-delay` | Forced delay between probes | Real stealth — evades simple rate-based IDS thresholds far better than `-T1` alone |
     47 | `--min-parallelism` / `--max-parallelism` | Probes in flight simultaneously | Fine-grained alternative to timing templates on congested or lossy networks |
     48 
     49 ```bash
     50 # Fast internal network, but don't crash the one flaky IoT device on it
     51 sudo nmap -p- --min-rate 2000 --max-rate 5000 --host-timeout 5m 10.0.0.0/24
     52 
     53 # Scanning over a slow VPN pivot — stop false "filtered" results from RTT timeouts
     54 sudo nmap -sS --initial-rtt-timeout 500ms --max-rtt-timeout 4s -p 1-1000 172.16.5.10
     55 ```
     56 
     57 > **Tip — The Rate-Limit Bypass Almost Nobody Uses.** Many Linux hosts and firewalls **rate-limit RST/ICMP unreachable responses** — this makes closed/filtered ports look identical and skews your results without you realising it.
     58 > ```bash
     59 > sudo nmap -sS --defeat-rst-ratelimit -p- 10.10.10.5
     60 > sudo nmap -sU --defeat-icmp-ratelimit --top-ports 200 10.10.10.5
     61 > ```
     62 > 1. **`--defeat-rst-ratelimit`** — keeps probing past a detected RST rate limit instead of assuming "filtered"
     63 > 2. **`--defeat-icmp-ratelimit`** — same idea for UDP scans relying on ICMP port-unreachable
     64 > 3. Without these, a rate-limited Linux target can make an open UDP port look closed/filtered — a classic source of false negatives
     65 
     66 ---
     67 
     68 ## Firewall & IDS Evasion
     69 
     70 > **Danger — Authorisation Required.** Every technique below changes how your traffic looks to defensive tooling. Only use these within signed RoE scope — evasion outside authorised engagements is a fast way to turn a pentest into a criminal case.
     71 
     72 ### Non-Standard Scan Types (Exploit RFC 793 Gaps)
     73 
     74 | Flag | Scan Type | Why It Evades Simple Filters |
     75 |---|---|---|
     76 | `-sN` | NULL scan (no flags set) | Many stateless ACLs only match SYN/ACK patterns — a flagless packet slips through unnoticed |
     77 | `-sF` | FIN scan | Same idea — closed ports RST, open/filtered stay silent, and it isn't a "connection attempt" to naive logging |
     78 | `-sX` | Xmas scan (FIN+PSH+URG set) | "Lights up like a Christmas tree" — again exploits RFC 793 behaviour most firewalls never account for |
     79 | `-sA` | ACK scan | Doesn't determine open/closed — determines **filtered vs unfiltered**, i.e. maps firewall rule sets directly |
     80 | `-sW` | Window scan | Variant of ACK scan using TCP window size quirks to infer open ports on some stacks |
     81 | `-sM` | Maimon scan | FIN/ACK combo — exploits certain BSD-derived stack behaviour |
     82 | `-sY` / `-sZ` | SCTP INIT / COOKIE-ECHO scan | Almost nobody scans [SCTP](https://en.wikipedia.org/wiki/Stream_Control_Transmission_Protocol) — telecom/signalling and some VoIP infra runs on it and is rarely monitored |
     83 | `-sO` | IP protocol scan | Finds *which protocols* (not ports) a host speaks — reveals hidden GRE tunnels, ESP/IPsec, OSPF |
     84 
     85 > **Warning — These Scan Types Need Root and Have Blind Spots.**
     86 > 1. All of `-sN`/`-sF`/`-sX`/`-sM` **require raw socket access** (root/sudo) and only work reliably against Unix-like TCP stacks per RFC 793 — Windows targets typically respond with RST to everything, making results useless there
     87 > 2. These scans **cannot distinguish "open" from "filtered"** — silence means either. Confirm with a normal `-sS` or targeted service probe afterward
     88 
     89 ### Packet Manipulation
     90 
     91 ```bash
     92 # Fragment packets — splits the TCP header across multiple IP fragments
     93 sudo nmap -f 10.10.10.5              # 8-byte fragments
     94 sudo nmap -ff 10.10.10.5             # 16-byte fragments (double fragmentation)
     95 sudo nmap --mtu 24 10.10.10.5        # custom fragment size (must be multiple of 8)
     96 
     97 # Pad probes with junk data to break simple length-based IDS signatures
     98 sudo nmap --data-length 25 -p 80,443 10.10.10.5
     99 
    100 # Set a custom TTL to blend in with expected regional/hop-count profiles
    101 sudo nmap --ttl 128 10.10.10.5
    102 
    103 # Spoof or randomise your MAC address on local segments
    104 sudo nmap --spoof-mac 00:11:22:33:44:55 -e eth0 10.10.10.5
    105 sudo nmap --spoof-mac Apple -e eth0 10.10.10.5     # vendor-prefix randomisation
    106 sudo nmap --spoof-mac 0 -e eth0 10.10.10.5         # fully random MAC
    107 
    108 # Bad checksum probe — see how the firewall/IDS reacts to intentionally invalid packets
    109 sudo nmap --badsum 10.10.10.5
    110 ```
    111 
    112 > **Info — Command Breakdown.**
    113 > 1. **`-f` / `-ff` / `--mtu`** — fragmentation defeats older/simple IDS that fail to reassemble packets before signature matching; modern IDS mostly handles this correctly now, but it's a zero-cost addition to an evasion profile
    114 > 2. **`--data-length`** — randomises payload size so probes don't match a fixed-length scan signature
    115 > 3. **`--spoof-mac`** — useful on internal segments where MAC-based NAC/allowlisting exists, or simply to avoid leaving your real NIC vendor fingerprint in switch logs
    116 > 4. **`--badsum`** — a genuine target silently drops these; a host that *does* respond may indicate a security device doing packet processing in a naive way
    117 
    118 ### Decoys and Source Manipulation
    119 
    120 ```bash
    121 # Hide your real scan among decoy source IPs
    122 sudo nmap -D RND:10 10.10.10.5
    123 sudo nmap -D decoy1.com,decoy2.com,ME,decoy3.com 10.10.10.5
    124 
    125 # Scan from a "trusted" source port — some legacy firewalls allow traffic FROM port 53/20/88
    126 sudo nmap --source-port 53 -p- 10.10.10.5
    127 sudo nmap -g 88 -p 1-1000 10.10.10.5
    128 
    129 # Force a specific egress interface on a multi-homed attack box (common on pivots)
    130 sudo nmap -e tun0 10.10.10.5
    131 ```
    132 
    133 > **Warning — Decoys Are Weaker Than They Used to Be.**
    134 > 1. Modern IDS/SIEM correlates **behaviour and timing patterns**, not just source-IP counts — decoys mainly slow down manual log review now, not automated detection
    135 > 2. Decoy IPs must actually be **up and reachable**, or the target's SYN-ACKs to them generate RSTs that can reveal which "decoy" is fake
    136 > 3. `--source-port` only works against firewalls with genuinely naive "allow if source port = X" rules — increasingly rare but still found on legacy/embedded gear
    137 
    138 ---
    139 
    140 ## Idle (Zombie) Scanning
    141 
    142 > **Important — How Idle Scan Actually Works.** [Idle scanning (`-sI`)](https://nmap.org/book/idlescan.html) spoofs your source IP as a third-party "zombie" host, then infers port state purely by watching the **zombie's IP ID sequence** increment. The target only ever sees traffic from the zombie — never from you.
    143 > 1. Find a zombie: an idle host with a **predictable, incrementing global IPID sequence** (old printers, embedded devices, unpatched legacy boxes are common candidates)
    144 > 2. Nmap's own `ipidseq` NSE script screens hosts for IPID predictability
    145 
    146 ```bash
    147 # Step 1: Find a usable zombie on the network
    148 nmap -p80 --script ipidseq 192.168.1.0/24
    149 
    150 # Step 2: Run the idle scan through the identified zombie
    151 sudo nmap -sI 192.168.1.50 -p- 10.10.10.5
    152 ```
    153 
    154 > **Success — When This Is Worth the Setup Effort.**
    155 > 1. Fully deniable scanning — logs on the actual target show the **zombie's** IP, never yours
    156 > 2. Useful for mapping firewall rules from a "trusted internal" vantage point without routing through it directly
    157 > 3. Slow and fragile — busy or NAT'd zombies break the technique; treat it as a specialty tool, not a default workflow
    158 
    159 ---
    160 
    161 ## Host Discovery Tricks Beyond a Basic Ping
    162 
    163 > **Info — Custom Discovery Probes.** Default `-sn` ping discovery relies on ICMP echo, which is blocked by almost every modern firewall. These flags let you build a discovery probe firewalls don't expect:
    164 
    165 ```bash
    166 # TCP SYN discovery to specific "probably open" ports instead of ICMP
    167 sudo nmap -sn -PS22,80,443,3389 10.10.10.0/24
    168 
    169 # TCP ACK discovery — some stateless firewalls pass ACK packets through
    170 sudo nmap -sn -PA80,443 10.10.10.0/24
    171 
    172 # UDP discovery probe (DNS/NTP/SNMP ports often get a response even when ICMP is dead)
    173 sudo nmap -sn -PU53,161 10.10.10.0/24
    174 
    175 # SCTP INIT discovery
    176 sudo nmap -sn -PY 10.10.10.0/24
    177 
    178 # ICMP variants beyond plain echo
    179 sudo nmap -sn -PE -PP -PM 10.10.10.0/24    # echo, timestamp, netmask requests
    180 
    181 # IP protocol ping — useful when ICMP/TCP/UDP are all filtered but other IP protocols aren't
    182 sudo nmap -sn -PO 10.10.10.0/24
    183 
    184 # Skip ARP ping on local segments (ARP is usually more reliable, but sometimes you want raw IP-layer behaviour)
    185 sudo nmap -sn --disable-arp-ping 10.10.10.0/24
    186 
    187 # Resolve names via a specific DNS server instead of the system resolver
    188 nmap --dns-servers 8.8.8.8,1.1.1.1 -sn 10.10.10.0/24
    189 
    190 # Pure target enumeration — resolves/lists targets without sending a single packet to them
    191 nmap -sL 10.10.10.0/24
    192 ```
    193 
    194 > **Tip — `-sL` Is a Free Sanity Check.** Run `-sL` first on any new CIDR range before touching it with a real scan — it just does reverse-DNS/target-list resolution with **zero packets sent to the targets themselves**. Perfect for validating a scope file has no typos before you burn scan time on it.
    195 
    196 ---
    197 
    198 ## Scan Resume, Diffing & Continuous Recon
    199 
    200 > **Tip — Resume an Interrupted Scan.** A `-p-` scan against a large range that gets killed (SSH drop, laptop sleep, Ctrl+C) doesn't have to restart from zero:
    201 > ```bash
    202 > nmap -p- -oA big_scan 10.0.0.0/16
    203 > # ...interrupted...
    204 > nmap --resume big_scan.nmap
    205 > ```
    206 
    207 > **Example — Diffing Scans Over Time With `ndiff`.** [ndiff](https://nmap.org/ndiff/) ships with Nmap and compares two XML scan results — essential for continuous recon on long engagements or bug bounty monitoring.
    208 > ```bash
    209 > nmap -oX scan_day1.xml 10.10.10.5
    210 > # ...next day...
    211 > nmap -oX scan_day2.xml 10.10.10.5
    212 > ndiff scan_day1.xml scan_day2.xml
    213 > ```
    214 > 1. Highlights newly opened/closed ports, changed service versions, new hosts appearing on a range
    215 > 2. Run this on a cron job against in-scope external ranges during a multi-week engagement to catch new attack surface the moment it appears
    216 
    217 ### HTML Reporting
    218 
    219 ```bash
    220 nmap -oX scan.xml 10.10.10.5
    221 xsltproc scan.xml -o scan_report.html
    222 ```
    223 
    224 > **Info — Command Breakdown.**
    225 > 1. Nmap's XML output ships with a built-in XSL stylesheet reference — `xsltproc` (or any XSLT processor) turns it into a **clickable HTML report** with zero extra tooling
    226 > 2. Great for handing raw scan evidence to a non-technical stakeholder without teaching them to read `.nmap` text output
    227 
    228 ---
    229 
    230 ## NSE Tricks Beyond `--script=default,vuln`
    231 
    232 > **Info — Debugging and Extending NSE.**
    233 > ```bash
    234 > # See the raw NSE network traffic a script generates — invaluable when a script "hangs" or gives odd results
    235 > nmap --script-trace --script=http-enum -p80 10.10.10.5
    236 >
    237 > # After adding/editing a custom .nse script, refresh Nmap's script database
    238 > nmap --script-updatedb
    239 >
    240 > # Cross-reference every detected service version against a CVE database directly
    241 > nmap -sV --script=vulners 10.10.10.5
    242 > ```
    243 > 1. **`--script-trace`** — shows every packet sent/received by the NSE engine; the fastest way to debug "why is this script timing out"
    244 > 2. **`vulners`** — turns plain version detection into an instant CVE list with CVSS scores; massively underused compared to the generic `vuln` category
    245 
    246 > **Example — Scripts That Need NO Target At All.** Several NSE scripts operate purely on **broadcast/multicast traffic** on your local segment — no IP argument required:
    247 > ```bash
    248 > nmap --script broadcast-dhcp-discover
    249 > nmap --script broadcast-ping
    250 > nmap --script llmnr-resolve --script-args 'newtargets,llmnr-resolve.hostname=printer'
    251 > ```
    252 > 1. `broadcast-dhcp-discover` — requests a DHCP lease to reveal DHCP server, gateway, DNS, and lease policy, before you even have an IP configuration
    253 > 2. `broadcast-ping` — finds live hosts via broadcast ping where individual host discovery is filtered
    254 > 3. This category is a goldmine on internal engagements before you've even set a static IP
    255 
    256 ---
    257 
    258 ## IPv6 and Protocol-Level Recon
    259 
    260 > **Warning — IPv6 Is the Overlooked Attack Surface.**
    261 > 1. Enterprise firewalls and monitoring are frequently **tuned only for IPv4** — the same host can have a wide-open IPv6 stack nobody is watching
    262 > 2. Always test both stacks explicitly:
    263 > ```bash
    264 > nmap -6 -sV fe80::1%eth0
    265 > nmap -6 -sV 2001:db8::1
    266 > ```
    267 > 3. `-sO` (IP protocol scan, shown above) is the easiest way to find **GRE tunnels, IPsec (ESP/AH), OSPF** — infrastructure most port-based scanning never reveals
    268 
    269 ---
    270 
    271 ## Companion Tool: Nping
    272 
    273 > **Info — [Nping](https://nmap.org/nping/) Overview.** Ships with Nmap. Built for crafting arbitrary raw packets — useful when Nmap's own flags don't give enough control.
    274 > 1. Custom TCP/UDP/ICMP/ARP packet crafting for testing specific firewall rules in isolation
    275 > 2. Can run in `--echo-client`/`--echo-server` mode to test round-trip packet mangling across a path
    276 > 3. Good for building a repeatable, minimal test case to hand to a network team ("this exact packet gets dropped here")
    277 
    278 ```bash
    279 # Craft a single custom TCP SYN packet to a specific port with custom flags/TTL
    280 nping --tcp -p 443 --flags syn --ttl 64 -c 1 10.10.10.5
    281 
    282 # ARP ping a local subnet (faster and more reliable than ICMP on local segments)
    283 sudo nping --arp -c 1 10.10.10.0/24
    284 ```
    285 
    286 ---
    287 
    288 ## Quick Reference — Flags Almost Nobody Uses
    289 
    290 | Flag | Purpose |
    291 |---|---|
    292 | `--stats-every 10s` + spacebar | Live progress without guessing if a scan has hung |
    293 | `--defeat-rst-ratelimit` / `--defeat-icmp-ratelimit` | Fix false "filtered" results from rate-limited targets |
    294 | `--host-timeout` | Don't let one dead host stall an entire range scan |
    295 | `-sO` | Find protocols (GRE/ESP/OSPF), not just ports |
    296 | `-sI` + `ipidseq` | Fully deniable scanning via a zombie host |
    297 | `-sL` | Zero-packet scope/target-list sanity check |
    298 | `--resume` | Never lose progress on a killed `-p-` scan again |
    299 | `ndiff` | Detect new attack surface across long engagements automatically |
    300 | `--script-trace` | Debug NSE scripts that hang or misbehave |
    301 | `--script=vulners` | Instant CVE/CVSS mapping from version detection |
    302 | `broadcast-*` NSE scripts | Enumerate before you even have an IP address |
    303 | `-6` | Test the IPv6 stack nobody else is monitoring |
    304 | `nping` | Craft the one exact packet you need when Nmap's flags aren't granular enough |
    305 
    306 ---
    307 
    308 ## References
    309 
    310 1. [Nmap Reference Guide](https://nmap.org/book/man.html)
    311 2. [Nmap — Idle Scan (-sI) Documentation](https://nmap.org/book/idlescan.html)
    312 3. [Nmap — Firewall/IDS Evasion and Spoofing](https://nmap.org/book/man-bypass-firewalls-ids.html)
    313 4. [ndiff — Nmap Scan Comparison Tool](https://nmap.org/ndiff/)
    314 5. [Nping Reference Guide](https://nmap.org/nping/)
    315 6. [NSE Documentation Portal](https://nmap.org/nsedoc/)
    316 7. [Vulners NSE Script](https://nmap.org/nsedoc/scripts/vulners.html)