Nmap.
Scan Types, Timing, And What NSE Actually Does.
A dense command reference: scan type flags and what each one actually tests for, host and port targeting options, timing templates, NSE script categories, and output formats. No live scanning here, just the switches.
Basic Syntax
One command shape, a target specification, and every flag below stacks onto it.
Command Shape And Target Specification
nmap [scan type] [options] [target] ├── Flags can be combined freely: nmap -sS -sV -O -T4 target runs a SYN scan with version and OS detection at timing template 4 └── Target specification accepts several forms in the same command 10.0.0.1 single host 10.0.0.0/24 CIDR block 10.0.0.1-50 range, last octet only scanme.nmap.org hostname, resolved before scanning -iL targets.txt read targets from a file, one per line // most scan types (-sS, -sA, -sN/-sF/-sX) need raw socket access, so run them as root/administrator
Scan Types
Different scan types trade speed, stealth, and accuracy differently, and some rely on TCP behavior that only works against certain stacks.
-sS — TCP SYN Scan
-sT — TCP Connect Scan
-sS, since every open port results in a fully logged connection.-sU — UDP Scan
-sA — ACK Scan
-sN / -sF / -sX — Null, FIN, Xmas
Host & Port Options
What gets probed, and whether Nmap bothers checking if a host is alive first.
-Pn
-Pn is common on internal engagements where discovery pings are filtered.-p / -p- / --top-ports
-p 80,443 scans specific ports, -p- scans all 65535, and --top-ports 100 scans the 100 most common ports by Nmap's frequency data. The default with no flag is the top 1000.-O — OS Detection
-sV — Version Detection
Timing Templates
A single flag that trades scan speed against stealth and reliability, instead of tuning a dozen individual parameters by hand.
-T0 / -T1 — Paranoid / Sneaky
-T2 / -T3 — Polite / Normal
-T4 — Aggressive
-T5 — Insane
NSE Scripts
The Nmap Scripting Engine turns a port scanner into a lightweight vulnerability and enumeration tool.
-sC / --script=default
Script Categories
--script=safe— scripts unlikely to crash the target or affect it negatively--script=vuln— checks for specific known vulnerabilities--script=auth— tests for weak or default credentials--script=discovery— enumerates more information about the target (shares, users, etc.)--script=intrusive— scripts that risk crashing the target or triggering defenses; not "safe" by NSE's own labeling
Targeted Script Example
nmap -p 443 --script ssl-enum-ciphers target enumerates the TLS cipher suites a host accepts on port 443, useful for spotting weak or deprecated ciphers still enabled on a service.Output Formats
Pick the format based on what reads it next: a human, a parser, or grep.
-oN — Normal
-oX or -oG are better choices when another tool needs to consume the results.-oX — XML
-oG — Grepable
grep/awk one-liner during live triage.-oA — All Formats At Once
-oA scan_results produces scan_results.nmap, scan_results.xml, and scan_results.gnmap in a single run, so the choice of format doesn't have to be made up front.