Nmap is the sharpest network scanner ever written and most people use it like a toy. One command tells you every door a machine has open. This guide shows exactly how Nmap thinks — ports, scan types, real commands — explained so simple a kid gets it.
TL;DR — Nmap knocks on every port of a target and reports which doors open. SYN scan for speed, version scan for detail, scripts for vulnerabilities. Cheat sheet waits at the bottom of the page.
1. WHAT A PORT IS (HOUSE VERSION)
A computer on the network is a house. A port is a door on that house. Every service that talks to the outside world sits behind its own door. Web server on door 80. Encrypted web on door 443. Remote shell on door 22. Database on door 3306. There are 65,535 doors on every house and most house owners leave half of them wide open without knowing.
Nmap is the guy who walks down the street and knocks on every single door. Knock, listen, write down what answered. That is the entire tool. Everything else is detail.
Why care? Because the door nobody watches is the door that gets walked through. An old file server sitting on port 445. A debug panel on port 8080. A database with no password on port 27017. You do not find those by guessing. You find them by scanning.
2. THE FIRST SCAN (DO THIS NOW)
Install Nmap from nmap.org, open a terminal, type this:
That is it. Nmap knocks on the 1,000 most common doors of your router and prints which ones opened. On your own network, right now, you will see something like:
Three doors open. SSH for remote admin, HTTP and HTTPS for its web panel. Every other knock came back locked. In two seconds you know what that machine does.
Scan yourself next — scan YOUR public IP and watch your own house from the street:
Whatever you see, an attacker sees the same thing. That is the point of running it first.
3. THE THREE KNOCKS (SCAN TYPES)
Nmap has different ways of knocking and each one trades speed for noise.
The SYN scan is the classic. Here is what happens inside it: your machine sends a SYN packet — the first knock of a handshake. The target replies SYN-ACK, meaning door is open, come in. Instead of completing the handshake, your machine backs off and never says hello. The target remembers a knock that never finished. Less log noise than a full connect, twice the speed. This is the scan every pentester runs by default:
That command scans an entire subnet — 256 machines — with the quiet knock, fast timing. On a home network it finishes while you blink.
4. COMMANDS THAT ACTUALLY MATTER
Forget the 300-page manual. These ten commands cover 95% of real work.
Read the -sn one again. No ports touched at all — it only asks "which machines are awake?" ARP packets on the local network, nothing else. That is your first move on any new network: map the living hosts before knocking on doors.
5. READING THE OUTPUT LIKE A HUNTER
Nmap output is four pieces of information and all four tell a story.
PORT — which door. 80 is web, 22 is SSH, 3306 is MySQL, 445 is Windows file sharing. Learn these numbers, they repeat forever.
STATE — open means answered. filtered means a firewall swallowed your knock. closed means the door exists but nobody is behind it. closed and open are honest answers. filtered is a wall.
SERVICE — what lives there. If port 8080 says http-proxy, look at it in a browser. If 3306 says mysql, it is a database talking to the world.
VERSION — the money. Apache 2.4.6 is from 2015. Old version equals known bugs. Search that exact version string and vulnerabilities fall out. This is how real break-ins start — not clever tricks, just an old version with a public exploit nobody patched.
6. SCRIPTS — THE PART THAT FINDS VULNS
Nmap ships with an entire script engine. Same tool, now it does the thinking for you.
The vuln script alone is worth memorizing. It runs NSE checks against every open door: heartbleed, shellshock, MS17-010 — the classics. One command, target, list of likely holes.
7. SPEED WITHOUT BURNING IT DOWN
-T4 is the default speed everyone uses. It is fast and stable on local networks. -T5 is a scream — packets fly before replies land, results get lost, firewalls notice. Use -T5 only on networks you own and never over the internet.
Fragmentation (-f) splits your packets into tiny pieces so lazy firewalls that read whole headers let them pass. Decoy (-D) sends knocks from fake addresses mixed with yours so logs point at ghosts. Source spoofing (-S) makes the knock come from an IP you choose — only works where you control the routing, which is almost nowhere, but worth knowing.
For big jobs, feed Nmap a list and let it run:
-oA writes the results in three formats at once — normal, XML, and grepable. The XML feeds into other tools. The normal file goes into your report.
8. FIELD CHEAT SHEET
Print this one too. Cheat sheets beat memory every time.
9. RULE OF ENGAGEMENT
Scan only what you own or what a contract puts in scope. Scanning your own router, your own lab, your own cloud instances — do it today. Pointing scans at someone else's network without permission is a crime in most countries, and the packets do not lie about where they came from. Authorized scopes only. Every bug bounty program allows scanning inside their scope — read it, then fire.
— RELATED GUIDES —
Two commands in, whole network out. Nmap tells you what exists — every open door, every old version, every lazy firewall. Map the hosts, knock the doors, read the versions, then go after what you are authorized to break. The cheat sheet is printed and the scanner is installed. Run the first sweep now.
TL;DR — Nmap knocks on every port of a target and reports which doors open. SYN scan for speed, version scan for detail, scripts for vulnerabilities. Cheat sheet waits at the bottom of the page.
1. WHAT A PORT IS (HOUSE VERSION)
A computer on the network is a house. A port is a door on that house. Every service that talks to the outside world sits behind its own door. Web server on door 80. Encrypted web on door 443. Remote shell on door 22. Database on door 3306. There are 65,535 doors on every house and most house owners leave half of them wide open without knowing.
Nmap is the guy who walks down the street and knocks on every single door. Knock, listen, write down what answered. That is the entire tool. Everything else is detail.
Why care? Because the door nobody watches is the door that gets walked through. An old file server sitting on port 445. A debug panel on port 8080. A database with no password on port 27017. You do not find those by guessing. You find them by scanning.
2. THE FIRST SCAN (DO THIS NOW)
Install Nmap from nmap.org, open a terminal, type this:
Bash:
nmap 192.168.1.1
That is it. Nmap knocks on the 1,000 most common doors of your router and prints which ones opened. On your own network, right now, you will see something like:
Code:
Starting Nmap 7.94 ( https://nmap.org )
Nmap scan report for 192.168.1.1
Host is up (0.003s latency).
Not shown: 997 closed tcp ports
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
Three doors open. SSH for remote admin, HTTP and HTTPS for its web panel. Every other knock came back locked. In two seconds you know what that machine does.
Scan yourself next — scan YOUR public IP and watch your own house from the street:
Bash:
nmap your-ip-here
Whatever you see, an attacker sees the same thing. That is the point of running it first.
3. THE THREE KNOCKS (SCAN TYPES)
Nmap has different ways of knocking and each one trades speed for noise.
| Flag | Knock type | What it does |
| -sT | Full connect | Opens the door fully, says hello, closes it. Loud. Logs show you clearly. |
| -sS | SYN scan | The half-knock. Touches the door and walks away before hello. Fast and quiet. |
| -sU | UDP scan | Knocks on the back windows. Slow, but DNS and SNMP hide there. |
| -sV | Version probe | Asks each open door what software is behind it and how old it is. |
| -O | OS guess | Reads the way the house breathes to guess Windows, Linux, or a router. |
The SYN scan is the classic. Here is what happens inside it: your machine sends a SYN packet — the first knock of a handshake. The target replies SYN-ACK, meaning door is open, come in. Instead of completing the handshake, your machine backs off and never says hello. The target remembers a knock that never finished. Less log noise than a full connect, twice the speed. This is the scan every pentester runs by default:
Bash:
nmap -sS -T4 10.0.0.0/24
That command scans an entire subnet — 256 machines — with the quiet knock, fast timing. On a home network it finishes while you blink.
4. COMMANDS THAT ACTUALLY MATTER
Forget the 300-page manual. These ten commands cover 95% of real work.
Bash:
# Fast sweep of a whole subnet — who is alive?
nmap -sn 192.168.1.0/24
# The daily driver — SYN scan with service versions
nmap -sS -sV -T4 10.0.0.5
# Scan every single port, not just 1,000
nmap -p- -T4 10.0.0.5
# UDP is where the forgotten services live
nmap -sU --top-ports 50 10.0.0.5
# OS and default scripts in one shot
nmap -O -sV -T4 10.0.0.5
# Aggressive mode — everything, no politeness
nmap -A -T4 10.0.0.5
# Output results to a file for the report
nmap -sS -oN scan.txt 10.0.0.5
# Bypass a basic firewall with fragmentation
nmap -f -T4 10.0.0.5
# Slow down so you look like normal traffic
nmap -T2 --scan-delay 1s 10.0.0.5
# Check if a specific door is open
nmap -p 3306 10.0.0.5
Read the -sn one again. No ports touched at all — it only asks "which machines are awake?" ARP packets on the local network, nothing else. That is your first move on any new network: map the living hosts before knocking on doors.
5. READING THE OUTPUT LIKE A HUNTER
Nmap output is four pieces of information and all four tell a story.
Code:
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4p1
80/tcp open http Apache 2.4.6
PORT — which door. 80 is web, 22 is SSH, 3306 is MySQL, 445 is Windows file sharing. Learn these numbers, they repeat forever.
STATE — open means answered. filtered means a firewall swallowed your knock. closed means the door exists but nobody is behind it. closed and open are honest answers. filtered is a wall.
SERVICE — what lives there. If port 8080 says http-proxy, look at it in a browser. If 3306 says mysql, it is a database talking to the world.
VERSION — the money. Apache 2.4.6 is from 2015. Old version equals known bugs. Search that exact version string and vulnerabilities fall out. This is how real break-ins start — not clever tricks, just an old version with a public exploit nobody patched.
6. SCRIPTS — THE PART THAT FINDS VULNS
Nmap ships with an entire script engine. Same tool, now it does the thinking for you.
Bash:
# Find misconfigs and known vulns on open ports
nmap --script vuln 10.0.0.5
# Grab titles and headers from every web server
nmap --script http-title,http-headers -p80,443 10.0.0.5
# Bruteforce SSH logins (your own lab only)
nmap --script ssh-brute -p22 10.0.0.5
# List SSL certificates — often leak internal hostnames
nmap --script ssl-cert -p443 target.com
The vuln script alone is worth memorizing. It runs NSE checks against every open door: heartbleed, shellshock, MS17-010 — the classics. One command, target, list of likely holes.
7. SPEED WITHOUT BURNING IT DOWN
-T4 is the default speed everyone uses. It is fast and stable on local networks. -T5 is a scream — packets fly before replies land, results get lost, firewalls notice. Use -T5 only on networks you own and never over the internet.
Fragmentation (-f) splits your packets into tiny pieces so lazy firewalls that read whole headers let them pass. Decoy (-D) sends knocks from fake addresses mixed with yours so logs point at ghosts. Source spoofing (-S) makes the knock come from an IP you choose — only works where you control the routing, which is almost nowhere, but worth knowing.
For big jobs, feed Nmap a list and let it run:
Bash:
nmap -iL targets.txt -sS -T4 -oA full-sweep
-oA writes the results in three formats at once — normal, XML, and grepable. The XML feeds into other tools. The normal file goes into your report.
8. FIELD CHEAT SHEET
| Task | Command |
| Who is alive? | nmap -sn 192.168.1.0/24 |
| Standard scan | nmap -sS -sV -T4 target |
| All 65,535 ports | nmap -p- -T4 target |
| UDP top 50 | nmap -sU --top-ports 50 target |
| OS + scripts | nmap -A -T4 target |
| Find vulns | nmap --script vuln target |
| Quiet timing | nmap -T2 --scan-delay 1s target |
| Firewall bypass | nmap -f -T4 target |
| Save everything | nmap -sS -oA results target |
Print this one too. Cheat sheets beat memory every time.
9. RULE OF ENGAGEMENT
Scan only what you own or what a contract puts in scope. Scanning your own router, your own lab, your own cloud instances — do it today. Pointing scans at someone else's network without permission is a crime in most countries, and the packets do not lie about where they came from. Authorized scopes only. Every bug bounty program allows scanning inside their scope — read it, then fire.
— RELATED GUIDES —
- Google Dorks List: 40 Ready-to-Run Dorks for 2026
- SQL Injection Dorks: The 2026 Master Collection
- Subdomain Takeover 2026: The DNS Gap Nobody Scans
- Botnet Attacks: From Mirai to MaaS in 2026
- SQL Injection Explained: The Only Guide You Need in 2026
- Money Mule Guide: Roles, Rates, and Real Risk
- Cashout OpSec: Discipline After the Exit
Two commands in, whole network out. Nmap tells you what exists — every open door, every old version, every lazy firewall. Map the hosts, knock the doors, read the versions, then go after what you are authorized to break. The cheat sheet is printed and the scanner is installed. Run the first sweep now.
Last edited: