Blacksec

Administrator
Staff member
ROOT
VIP
Nmap is the sharpest network scanner ever written and most people use it like a toy. One command tells you every door a machine has open. This guide shows exactly how Nmap thinks — ports, scan types, real commands — explained so simple a kid gets it.

TL;DR — Nmap knocks on every port of a target and reports which doors open. SYN scan for speed, version scan for detail, scripts for vulnerabilities. Cheat sheet waits at the bottom of the page.

1. WHAT A PORT IS (HOUSE VERSION)

A computer on the network is a house. A port is a door on that house. Every service that talks to the outside world sits behind its own door. Web server on door 80. Encrypted web on door 443. Remote shell on door 22. Database on door 3306. There are 65,535 doors on every house and most house owners leave half of them wide open without knowing.

Nmap is the guy who walks down the street and knocks on every single door. Knock, listen, write down what answered. That is the entire tool. Everything else is detail.

Why care? Because the door nobody watches is the door that gets walked through. An old file server sitting on port 445. A debug panel on port 8080. A database with no password on port 27017. You do not find those by guessing. You find them by scanning.

2. THE FIRST SCAN (DO THIS NOW)

Install Nmap from nmap.org, open a terminal, type this:

Bash:
nmap 192.168.1.1

That is it. Nmap knocks on the 1,000 most common doors of your router and prints which ones opened. On your own network, right now, you will see something like:

Code:
Starting Nmap 7.94 ( https://nmap.org )
Nmap scan report for 192.168.1.1
Host is up (0.003s latency).
Not shown: 997 closed tcp ports
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https

Three doors open. SSH for remote admin, HTTP and HTTPS for its web panel. Every other knock came back locked. In two seconds you know what that machine does.

Scan yourself next — scan YOUR public IP and watch your own house from the street:

Bash:
nmap your-ip-here

Whatever you see, an attacker sees the same thing. That is the point of running it first.

3. THE THREE KNOCKS (SCAN TYPES)

Nmap has different ways of knocking and each one trades speed for noise.

FlagKnock typeWhat it does
-sTFull connectOpens the door fully, says hello, closes it. Loud. Logs show you clearly.
-sSSYN scanThe half-knock. Touches the door and walks away before hello. Fast and quiet.
-sUUDP scanKnocks on the back windows. Slow, but DNS and SNMP hide there.
-sVVersion probeAsks each open door what software is behind it and how old it is.
-OOS guessReads the way the house breathes to guess Windows, Linux, or a router.

The SYN scan is the classic. Here is what happens inside it: your machine sends a SYN packet — the first knock of a handshake. The target replies SYN-ACK, meaning door is open, come in. Instead of completing the handshake, your machine backs off and never says hello. The target remembers a knock that never finished. Less log noise than a full connect, twice the speed. This is the scan every pentester runs by default:

Bash:
nmap -sS -T4 10.0.0.0/24

That command scans an entire subnet — 256 machines — with the quiet knock, fast timing. On a home network it finishes while you blink.

4. COMMANDS THAT ACTUALLY MATTER

Forget the 300-page manual. These ten commands cover 95% of real work.

Bash:
# Fast sweep of a whole subnet — who is alive?
nmap -sn 192.168.1.0/24

# The daily driver — SYN scan with service versions
nmap -sS -sV -T4 10.0.0.5

# Scan every single port, not just 1,000
nmap -p- -T4 10.0.0.5

# UDP is where the forgotten services live
nmap -sU --top-ports 50 10.0.0.5

# OS and default scripts in one shot
nmap -O -sV -T4 10.0.0.5

# Aggressive mode — everything, no politeness
nmap -A -T4 10.0.0.5

# Output results to a file for the report
nmap -sS -oN scan.txt 10.0.0.5

# Bypass a basic firewall with fragmentation
nmap -f -T4 10.0.0.5

# Slow down so you look like normal traffic
nmap -T2 --scan-delay 1s 10.0.0.5

# Check if a specific door is open
nmap -p 3306 10.0.0.5

Read the -sn one again. No ports touched at all — it only asks "which machines are awake?" ARP packets on the local network, nothing else. That is your first move on any new network: map the living hosts before knocking on doors.

5. READING THE OUTPUT LIKE A HUNTER

Nmap output is four pieces of information and all four tell a story.

Code:
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.4p1
80/tcp open http Apache 2.4.6

PORT — which door. 80 is web, 22 is SSH, 3306 is MySQL, 445 is Windows file sharing. Learn these numbers, they repeat forever.

STATE — open means answered. filtered means a firewall swallowed your knock. closed means the door exists but nobody is behind it. closed and open are honest answers. filtered is a wall.

SERVICE — what lives there. If port 8080 says http-proxy, look at it in a browser. If 3306 says mysql, it is a database talking to the world.

VERSION — the money. Apache 2.4.6 is from 2015. Old version equals known bugs. Search that exact version string and vulnerabilities fall out. This is how real break-ins start — not clever tricks, just an old version with a public exploit nobody patched.

6. SCRIPTS — THE PART THAT FINDS VULNS

Nmap ships with an entire script engine. Same tool, now it does the thinking for you.

Bash:
# Find misconfigs and known vulns on open ports
nmap --script vuln 10.0.0.5

# Grab titles and headers from every web server
nmap --script http-title,http-headers -p80,443 10.0.0.5

# Bruteforce SSH logins (your own lab only)
nmap --script ssh-brute -p22 10.0.0.5

# List SSL certificates — often leak internal hostnames
nmap --script ssl-cert -p443 target.com

The vuln script alone is worth memorizing. It runs NSE checks against every open door: heartbleed, shellshock, MS17-010 — the classics. One command, target, list of likely holes.

7. SPEED WITHOUT BURNING IT DOWN

-T4 is the default speed everyone uses. It is fast and stable on local networks. -T5 is a scream — packets fly before replies land, results get lost, firewalls notice. Use -T5 only on networks you own and never over the internet.

Fragmentation (-f) splits your packets into tiny pieces so lazy firewalls that read whole headers let them pass. Decoy (-D) sends knocks from fake addresses mixed with yours so logs point at ghosts. Source spoofing (-S) makes the knock come from an IP you choose — only works where you control the routing, which is almost nowhere, but worth knowing.

For big jobs, feed Nmap a list and let it run:

Bash:
nmap -iL targets.txt -sS -T4 -oA full-sweep

-oA writes the results in three formats at once — normal, XML, and grepable. The XML feeds into other tools. The normal file goes into your report.

8. FIELD CHEAT SHEET

TaskCommand
Who is alive?nmap -sn 192.168.1.0/24
Standard scannmap -sS -sV -T4 target
All 65,535 portsnmap -p- -T4 target
UDP top 50nmap -sU --top-ports 50 target
OS + scriptsnmap -A -T4 target
Find vulnsnmap --script vuln target
Quiet timingnmap -T2 --scan-delay 1s target
Firewall bypassnmap -f -T4 target
Save everythingnmap -sS -oA results target

Print this one too. Cheat sheets beat memory every time.

9. RULE OF ENGAGEMENT

Scan only what you own or what a contract puts in scope. Scanning your own router, your own lab, your own cloud instances — do it today. Pointing scans at someone else's network without permission is a crime in most countries, and the packets do not lie about where they came from. Authorized scopes only. Every bug bounty program allows scanning inside their scope — read it, then fire.

— RELATED GUIDES —

Two commands in, whole network out. Nmap tells you what exists — every open door, every old version, every lazy firewall. Map the hosts, knock the doors, read the versions, then go after what you are authorized to break. The cheat sheet is printed and the scanner is installed. Run the first sweep now.
 
Last edited: