H3AD-REF / CHEATSHEETS / NMAP SCAN REFERENCE

Nmap.
Scan Types, Timing, And What NSE Actually Does.

A dense command reference: scan type flags and what each one actually tests for, host and port targeting options, timing templates, NSE script categories, and output formats. No live scanning here, just the switches.

Basic Syntax

One command shape, a target specification, and every flag below stacks onto it.

Command Shape And Target Specification

nmap [scan type] [options] [target]
├── Flags can be combined freely: nmap -sS -sV -O -T4 target runs a SYN scan with version and OS detection at timing template 4
└── Target specification accepts several forms in the same command
    10.0.0.1              single host
    10.0.0.0/24           CIDR block
    10.0.0.1-50           range, last octet only
    scanme.nmap.org       hostname, resolved before scanning
    -iL targets.txt       read targets from a file, one per line
    // most scan types (-sS, -sA, -sN/-sF/-sX) need raw socket access, so run them as root/administrator

Scan Types

Different scan types trade speed, stealth, and accuracy differently, and some rely on TCP behavior that only works against certain stacks.

SCAN

-sS — TCP SYN Scan

The default for privileged users, and the most common choice
Sends a SYN, reads the response, and never completes the handshake (no ACK). Faster and quieter than a full connect scan, since most targets and IDS sensors log a completed connection more readily than a half-open one.
SCAN

-sT — TCP Connect Scan

Completes the full three-way handshake
Used automatically when raw socket access isn't available (non-root, or scanning through certain proxies). Slower and more visible than -sS, since every open port results in a fully logged connection.
SCAN

-sU — UDP Scan

Slower and less reliable than TCP scanning by nature of the protocol
UDP has no handshake to probe, so Nmap infers state from ICMP port-unreachable responses (closed) or a protocol-specific response (open). A firewall that silently drops UDP makes every port look "open|filtered."
SCAN

-sA — ACK Scan

Maps firewall rules, doesn't determine open vs closed
Sends an ACK with no prior SYN. A RST response means unfiltered (the firewall let the packet through, whether or not the port is open); no response means filtered. Useful for mapping stateful firewall rules, not for finding open services.
SCAN

-sN / -sF / -sX — Null, FIN, Xmas

Stealth scans that exploit RFC 793 TCP behavior
Send a packet with no flags, only FIN, or FIN+PSH+URG set. A closed port replies RST; an open port stays silent. These don't work against Windows, which replies RST regardless of state, breaking the technique entirely on that OS family.

Host & Port Options

What gets probed, and whether Nmap bothers checking if a host is alive first.

OPTION

-Pn

Skip host discovery, treat every target as up
Without this, Nmap pings a host first and skips scanning it if there's no reply. Firewalls that drop ICMP make hosts look down even when they aren't, so -Pn is common on internal engagements where discovery pings are filtered.
OPTION

-p / -p- / --top-ports

Controls which ports actually get probed
-p 80,443 scans specific ports, -p- scans all 65535, and --top-ports 100 scans the 100 most common ports by Nmap's frequency data. The default with no flag is the top 1000.
OPTION

-O — OS Detection

Fingerprints the target's TCP/IP stack
Compares response quirks (initial TTL, window size, TCP options ordering) against Nmap's OS fingerprint database. Needs at least one open and one closed port on the target to produce a confident guess.
OPTION

-sV — Version Detection

Identifies the service and version listening on each open port
Sends a series of probes and matches the response against a signature database, distinguishing e.g. nginx from Apache, or OpenSSH 7.4 from 9.x, rather than just reporting "port 22 open."

Timing Templates

A single flag that trades scan speed against stealth and reliability, instead of tuning a dozen individual parameters by hand.

TIMING

-T0 / -T1 — Paranoid / Sneaky

Minutes between probes
Built for evading intrusion detection over a long window. Impractically slow for anything but a targeted, low-and-slow engagement against a heavily monitored target.
TIMING

-T2 / -T3 — Polite / Normal

T3 is Nmap's default with no timing flag set
Polite (-T2) deliberately slows down to use less bandwidth and target load. Normal (-T3) is the baseline every other template is measured against.
TIMING

-T4 — Aggressive

The commonly recommended default for a reliable, reasonably fast network
Assumes a stable, low-latency connection to the target and scans significantly faster than the default. This is the template most engagement notes and cheat-sheets recommend as a sane starting point.
TIMING

-T5 — Insane

Sacrifices accuracy for raw speed
Assumes an unusually fast and reliable network and times out slow responses quickly, which means it can miss ports or hosts on anything less than an ideal connection. Rarely the right default.

NSE Scripts

The Nmap Scripting Engine turns a port scanner into a lightweight vulnerability and enumeration tool.

NSE

-sC / --script=default

Runs the default script set automatically
A curated set of low-impact, generally safe scripts that run without extra flags. Good for a first pass; not a substitute for a targeted vuln scan.
NSE

Script Categories

--script accepts a category name, not just a filename
  • --script=safe — scripts unlikely to crash the target or affect it negatively
  • --script=vuln — checks for specific known vulnerabilities
  • --script=auth — tests for weak or default credentials
  • --script=discovery — enumerates more information about the target (shares, users, etc.)
  • --script=intrusive — scripts that risk crashing the target or triggering defenses; not "safe" by NSE's own labeling
NSE

Targeted Script Example

Scripts can take arguments, not just a target
nmap -p 443 --script ssl-enum-ciphers target enumerates the TLS cipher suites a host accepts on port 443, useful for spotting weak or deprecated ciphers still enabled on a service.

Output Formats

Pick the format based on what reads it next: a human, a parser, or grep.

OUTPUT

-oN — Normal

The same text Nmap prints to the terminal, saved to a file
Readable as-is, but not the easiest format to script against — -oX or -oG are better choices when another tool needs to consume the results.
OUTPUT

-oX — XML

The format most parsing tools and reporting scripts expect
Structured and stable across Nmap versions, which is why most third-party tools (including report generators and other scanners that import Nmap results) expect XML input over any other format.
OUTPUT

-oG — Grepable

One line per host, built for quick shell-level filtering
Deprecated by the Nmap project in favor of XML for anything programmatic, but still genuinely useful for a fast grep/awk one-liner during live triage.
OUTPUT

-oA — All Formats At Once

Writes .nmap, .xml, and .gnmap with one shared base filename
-oA scan_results produces scan_results.nmap, scan_results.xml, and scan_results.gnmap in a single run, so the choice of format doesn't have to be made up front.