Cheatsheet
Nmap
Scan types, port selection, output and timing switches, in the order you reach for them.
28/28
Discovery
Establish what is present before scanning ports.
- Ping sweep a subnet
nmap -sn 192.0.2.0/24 - ARP-style local discovery (needs privileges)
sudo nmap -sn 192.0.2.0/24On-LAN ARP is more reliable than ICMP - TCP SYN ping on allowed ports
nmap -PS22,80,443 192.0.2.0/24 - Treat hosts as up (ICMP blocked)
nmap -Pn 192.0.2.10 - List targets only, send nothing
nmap -sL 192.0.2.0/24
Ports & protocols
- Top 1000 ports (default)
nmap 192.0.2.10 - All 65535 TCP ports
nmap -p- 192.0.2.10 - Port list and ranges
nmap -p 22,80,443,8000-8100 192.0.2.10 - Top N ports by frequency
nmap --top-ports 100 192.0.2.10 - UDP on a short list
sudo nmap -sU -p 53,123,161 192.0.2.10 - Mixed TCP+UDP
sudo nmap -sSU -p U:53,T:53,443 192.0.2.10
Scan techniques
- TCP connect (no raw sockets)
nmap -sT 192.0.2.10 - SYN half-open (privileged)
sudo nmap -sS 192.0.2.10 - Version detection
nmap -sV 192.0.2.10 - Default NSE scripts
nmap -sC 192.0.2.10 - OS detection
sudo nmap -O --osscan-limit 192.0.2.10 - Why a port is filtered
nmap -Pn --reason -p 80 192.0.2.10 - One named script with args
nmap --script http-headers --script-args http-headers.path=/ 192.0.2.10
Output & performance
- All formats with a prefix
nmap -oA scans/host-01 192.0.2.10 - XML only
nmap -oX scans/host.xml 192.0.2.10 - Append open ports for notes
grep 'open' scans/host-01.gnmap - Timing template (stay <=T3 on production)
nmap -T3 192.0.2.10 - Cap parallelism and retries
nmap --max-parallelism 20 --max-retries 1 192.0.2.10 - Don't let one host stall the run
nmap --host-timeout 5m --script-timeout 20s 192.0.2.10 - Resume from previous state
nmap --resume
Privilege checklist
- Grant raw-socket capability once
sudo setcap cap_net_raw,cap_net_admin=eip $(which nmap) - Confirm version and paths
nmap --version - Test before a long scan
nmap -v -p 22,80 192.0.2.10-v shows which scan type was actually selected