Skip to content

RustScan

Fast TCP port finder that hands off to Nmap

CommunityNetworking· Discovery & ReconBeginnerOpen sourceEntry revised 4 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Arch
  • Docker
  • Source

Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

3 commands documented

RustScan opens sockets aggressively to find listening ports quickly, then can invoke Nmap on just those ports for the detailed work. It is a discovery accelerator, not a replacement for Nmap's fingerprinting.

Supported platforms

7

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

port scanning, speed, nmap, batch

Dataset entry

rustscan.ts

Reviewed 2026-01-04

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

RecommendedHomebrew
brew install rustscan

Package availability follows your distribution and enabled repositories. Entry revised 4 Jan 2026 — confirm the current release on the project's own download page.

Commands

3 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Scan and pass through to Nmap

bash

Finds open TCP ports, then runs the supplied Nmap arguments against them.

rustscan -a 192.0.2.10 -- -sV -oA scans/rust-target

Notes

  • Everything after `--` goes to Nmap. Without it, RustScan only lists ports.

02Port range and batch size

bash

Controls the keyspace and how many sockets are attempted concurrently.

rustscan -a 192.0.2.10 -r 1-10000 --batch-size 2000
  • Large batch sizes exhaust file descriptors and can upset shared infrastructure.

03Raise the descriptor limit for the session

bash

RustScan's docs call out the soft file-descriptor limit as the usual constraint.

ulimit -n 65535 && rustscan -a 192.0.2.10

Notes

  • Persisting it in `/etc/security/limits.conf` is the documented machine-wide fix; prefer the per-session form on a lab box.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"failed to open socket / Too many open files"Cause 1/2

Possible causes

  • ulimit -n is lower than the concurrency requested.

Usual fix

Lower --batch-size or raise the session limit with `ulimit -n`.

ulimit -n 4096
Nmap never runs after `--`Cause 2/2

Possible causes

  • Nmap is not on PATH, or arguments were placed before the separator.

Usual fix

Put all Nmap arguments after `--` and confirm `nmap -V` works in the same shell.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking

Looking for alternatives?

Nmap, Masscan cover adjacent parts of the same job.

Compare side by side