Nmap Cheatsheet
Host discovery, port scanning, and service/script enumeration. For fast /16+ sweeps, pair with masscan then feed live hosts back to nmap for version detection.
Host discovery
# ARP/ICMP sweep on a local subnet (no port scan)
nmap -sn 192.168.1.0/24
# Ping-agnostic host discovery (use when ICMP is blocked)
nmap -Pn -sS -p 22,80,135,139,445,3389,5985 192.168.1.0/24
# Pull live hosts into a file for downstream tools
nmap -sn 10.0.0.0/16 -oG - | awk '/Up$/{print $2}' > live.txtPort scanning
# Fast top-100 ports
nmap -F 192.168.1.0/24 -oA fast_scan
# Full TCP sweep, tuned for internal speed
nmap -p- -T4 --min-rate 5000 --max-retries 2 target -oA full_tcp
# UDP top-50 (slow, noisy)
nmap -sU --top-ports 50 -T4 target -oA udp_top50
# Stealth SYN scan (requires root/CAP_NET_RAW)
nmap -sS -Pn -p- targetVersion + default scripts
# The standard "service enum" pass against common Windows/AD ports
nmap -sV -sC -p 21,22,23,25,53,80,88,110,135,139,143,389,443,445,464,\
593,636,1433,1521,2049,3268,3269,3306,3389,5432,5985,5986,8080,8443 \
target -oA servicesScript categories useful for internal/AD pentest
# SMB vuln & info
nmap --script "smb-vuln-*" -p445 target
nmap --script smb-os-discovery,smb-security-mode,smb2-security-mode,smb-enum-shares -p445 target
# LDAP
nmap --script "ldap-*" -p389,636,3268,3269 target
# Kerberos user enumeration (requires a userlist)
nmap -p88 --script krb5-enum-users --script-args krb5-enum-users.realm='CORP.LOCAL',userdb=users.txt target
# MSRPC
nmap --script msrpc-enum -p135 target
# HTTP discovery
nmap --script "http-title,http-enum,http-methods" -p80,443,8080,8443 targetMasscan handoff (for /16+ scopes)
# Masscan is orders of magnitude faster for discovery, but has no service detection
masscan -p1-65535 --rate 10000 10.0.0.0/16 -oL masscan.lst
# Pull unique host:port pairs, then nmap -sV only those
awk '/^open/{print $4":"$3}' masscan.lst | sort -u > targets.lst
nmap -sV -sC -Pn -iL <(cut -d: -f1 targets.lst | sort -u) -oA targetedOutput formats
nmap -oA run # all three: .nmap .gnmap .xml
nmap -oX run.xml # for XSLT/nessus-style parsing
nmap -oJ run.json # (requires --append-output and recent nmap)Timing & evasion (authorized engagements only)
# Slow / polite (avoid IDS thresholds)
nmap -T2 --max-rate 50 target
# Fragmented packets, source port spoof, decoy (detective controls testing)
nmap -f -g 53 -D RND:5 targetTool versions validated
- nmap >= 7.94
- masscan >= 1.3.2