Skip to content

Nmap

v7.95

Network discovery and security auditing

VerifiedNetworking· Discovery & ReconBeginnerNPSL (Nmap Public Source License)Open sourceEntry revised 18 Jan 2026
  • Windows
  • macOS
  • Linux
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Docker
  • Source

Overview

11 commands documented

Nmap (Network Mapper) sends purpose-built packets to hosts and infers what services are available, what their versions appear to be, and how a network filters traffic. It is the reference tool for host discovery, port scanning and service enumeration.

Beyond plain port checks it ships a scripting engine (NSE) for protocol-specific probing, output formats designed for later processing, and timing controls that let you trade network load for speed. Nmap is designed for authorized assessment of networks you own or are contracted to test.

Supported platforms

9

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

port scanning, service detection, recon, network, nse, discovery

Dataset entry

nmap.ts

Reviewed 2026-01-18

Installation

Grouped by platform. Elevation requirements are marked per method.

Winget (recommended)

Recommendedwinget

Installs the official Windows binary package, which bundles Npcap for raw-socket scanning.

Needs elevated privileges (sudo / Administrator).

winget install --id Insecure.Nmap -e
  • The Windows installer also offers Zenmap (GUI) and Ncat. Npcap is required for SYN scans and OS detection.

Official installer

AlternativeinstallerOfficial

Download the signed Windows installer from the project's download page.

  • Verify the version on the download page before installing on managed workstations.
Open official source

Package availability follows your distribution and enabled repositories. Entry revised 18 Jan 2026 — confirm the current release on the project's own download page.

Commands

11 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Basic scan of a single host

bash

Scans Nmap's 1,000 most common TCP ports and reports which are open. A sensible first pass on an authorized host.

nmap 192.0.2.10

Example

nmap 192.0.2.10

Example output

Illustrative only — real output depends on the target, version and your position on the network.

PORT     STATE  SERVICE
22/tcp   open   ssh
80/tcp   open   http
443/tcp  closed https

Notes

  • Without `-sV`, the SERVICE column is derived from port number only — it is a guess, not confirmation.

02Service version detection

bash

Probes each open port with protocol-specific queries and reports the banner or fingerprint it receives.

nmap -sV 192.0.2.10

Example

nmap -sV -p 80,443,8080 192.0.2.10

Example output

Illustrative only — real output depends on the target, version and your position on the network.

80/tcp open  http    nginx 1.22.1
443/tcp open  ssl/http  Apache httpd 2.4.57

Notes

  • `--version-intensity 0-9` trades probe count for accuracy; the default of 7 is fine for most work.
  • Version probes can disturb fragile embedded services — enumerate ports first on industrial gear.

03Default NSE scripts

bash

Runs the script category marked `default`, which gathers safe, high-signal information such as TLS certificates, title banners and well-known misconfigurations.

nmap -sC -sV 192.0.2.10

Example

nmap -sC -sV -p- -oA scans/web-01 192.0.2.10

Notes

  • Scripts live in `scripts/*.nse`; `-sC` is shorthand for `--script=default`.
  • Some scripts emit verbose requests. Check the script entry with `nmap --script-help http-slowloris` before running anything outside the default category.

04TCP SYN scan (half-open)

bash

Sends SYN packets and reads the response without completing the handshake. Faster and less noisy than a full connect scan.

sudo nmap -sS 192.0.2.10
  • Requires raw-socket privileges: root/admin on Linux, Npcap on Windows.

Notes

  • On Linux Nmap may also need `CAP_NET_RAW`/`CAP_NET_ADMIN` if you run it as a non-root user.
  • If SYN scanning is unavailable, Nmap falls back to `-sT` (full connect) — note the difference in your findings.

05Operating system fingerprinting

bash

Compares TCP/IP stack quirks against a fingerprint database and reports the most likely operating systems.

sudo nmap -O 192.0.2.10

Example output

Illustrative only — real output depends on the target, version and your position on the network.

Device type: general purpose
Running: Linux 5.X
OS CPE: cpe:/o:linux:linux_kernel:5.15
  • Requires root (or CAP_NET_RAW) because it uses raw IP probes.

Notes

  • Results are probabilistic. `--osscan-limit` restricts probing to hosts with at least one open and one closed port, which improves reliability.

06Scan all 65,535 TCP ports

bash

Replaces the default top-1000 port list with the full TCP port range so nothing is missed by assumption.

nmap -p- 192.0.2.10

Notes

  • Combine with `--top-ports 100` for a fast second pass on large ranges.
  • `-p 0-65535` is equivalent; `-p U:53,T:53` mixes UDP and TCP in a single invocation.

07Skip host discovery (filtered hosts)

bash

Treats hosts as up even when ICMP is blocked, so ports are probed even if the host does not answer pings.

nmap -Pn 192.0.2.10

Notes

  • Without discovery Nmap scans every address in a range — on a /24 that is 256 hosts. Scope carefully.
  • Use `-PS22,80,443` (TCP SYN ping) or `-PA80` when you want discovery through a specific allowed port.

08Ping sweep a local subnet

bash

Performs host discovery only, to list live addresses before any port work. The polite way to size a network.

nmap -sn 192.0.2.0/24

Example output

Illustrative only — real output depends on the target, version and your position on the network.

Nmap scan report for 192.0.2.1
Host is up (0.0021s latency).
MAC Address: AA:BB:CC:00:11:22 (Vendor)

Notes

  • On a local segment Nmap also uses ARP, which is far more reliable than ICMP — this usually needs root.

09Targeted UDP service scan

bash

Probes common UDP ports. UDP is slow and unreliable, so restrict it to a known port list.

sudo nmap -sU -p 53,67,68,123,161,500,5353 192.0.2.10
  • A full UDP port range scan is very slow and can flood low-power devices. Always restrict the port list.

Notes

  • Ports reported `open|filtered` are ambiguous: Nmap received no response, which is also what a firewall drop looks like.

10Save output in all formats

bash

Writes normal, XML and grepable output with one prefix, which keeps evidence organised for reporting.

nmap -sV -sC -oA scans/target-01 192.0.2.10

Notes

  • Produces `target-01.nmap`, `.xml` and `.gnmap`. XML is what most tools and note-taking frameworks import.
  • `-oG` output is convenient for `grep`, but the format is officially frozen and should not be relied on for long-lived parsers.

11Adjust scan timing

bash

Sets the timing template, which controls parallelism and retry timeouts.

nmap -T3 --max-parallelism 32 192.0.2.10
  • Higher templates (T4-T5) increase load on the target and on intermediate firewalls. On shared or production systems prefer T2-T3.

Notes

  • Use `--host-timeout 10m --max-retries 1` so one stubborn host does not dominate a scan window.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

First pass on an authorized web host

You have written scope for one host and need a defensible inventory of exposed TCP services.

  1. 1

    Confirm the host answers

    nmap -sn 192.0.2.10
  2. 2

    Enumerate services and default scripts, saving everything

    nmap -Pn -sV -sC -p- -oA scans/web-01 192.0.2.10
  3. 3

    Extract just the open ports for notes

    grep open scans/web-01.gnmap

You end up with a full port list, version guesses, script output in XML for import, and a plain-text file to quote in a report.

Verifying a firewall change

The network team says only 443 is reachable from the guest VLAN. Prove it from that segment.

  1. 1

    Scan the ports that should be closed

    nmap -Pn -p 22,80,443,445,3389 203.0.113.5
  2. 2

    Distinguish filtered from closed

    nmap -Pn -sV -p 80,443 --reason 203.0.113.5

`closed` means a host answered with RST; `filtered` means nothing came back. Only the second result proves a rule is doing the blocking.

What it is used for

  • Authorized scope inventory

    Build a factual list of exposed network services before an assessment or during a periodic review.

  • Hardening verification

    Confirm that a disabled service, patched banner or firewall rule actually behaves as documented.

  • Lab and CTF enumeration

    Standard first step in isolated ranges to see what a machine exposes.

  • Incident triage support

    Rapidly answer 'what was listening on this host at that time' when combined with logs.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"Only root may use a SYN scan on this system"Cause 1/5

Possible causes

  • The process lacks raw-socket privileges on Linux/macOS.
  • Windows install without Npcap, or Npcap installed without the raw-open feature.

Usual fix

Re-run with sudo (or grant CAP_NET_RAW/CAP_NET_ADMIN to the binary), or use a full connect scan with -sT, which does not need raw sockets.

sudo nmap -sS 192.0.2.10
sudo setcap cap_net_raw,cap_net_admin=eip $(which nmap)
All 1000 ports show "filtered" although the host is clearly liveCause 2/5

Possible causes

  • An upstream firewall drops the probe range and only allows specific ports.
  • Host discovery passed on a different protocol than the port probes.

Usual fix

Scan only the allowed ports, and use `-Pn` with `-sV --reason`. If ICMP/ACK probes are being dropped you will see no difference between filtered and dropped, so note it as a limitation in your report.

nmap -Pn -sV --reason -p 443,8443 192.0.2.10
Windows: "Couldn't find device Npcap Loopback" or libpcap errorCause 3/5

Possible causes

  • Npcap not installed, or installed without 'Install Npcap in WinPcap API-compatible Mode'.
  • Scanning localhost requires the loopback adapter option.

Usual fix

Reinstall Npcap from the Nmap download page and enable 'Support for loopback adapter' when scanning 127.0.0.1.

Scan hangs on one host while the rest finishCause 4/5

Possible causes

  • A host is rate-limiting, or a script is waiting on an unresponsive service.
  • No host timeout was configured.

Usual fix

Add per-host and per-script limits so a single target cannot stall the run.

nmap -Pn --host-timeout 5m --script-timeout 20s --max-retries 1 192.0.2.10
"Failed to resolve given hostname"Cause 5/5

Possible causes

  • Typo, missing DNS record, or the target is only reachable by IP.

Usual fix

Verify resolution with the platform resolver first, then scan the address directly and record the mapping in your notes.

Resolve-DnsName example.internal
getent hosts example.internal

Tips

  • Scan twice: once for coverage (`-p-`), once for detail (`-sV -sC` on the ports you found). It is faster than one giant scan with everything enabled.
  • Save XML (`-oX`) from the beginning. Re-formatting a completed scan is impossible without re-scanning the target.
  • `--script-help <name>` and the NSE category list tell you what a script actually sends. Read it before using anything outside `default`.
  • For internal ranges, resolve MAC vendors with `-Pn -sL` first; it is often enough to spot unexpected hardware.
  • Time templates change packet volume, not cleverness. On production networks stay at T3 or below.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking

Looking for alternatives?

Masscan, RustScan cover adjacent parts of the same job.

Compare side by side