Skip to Content
Red Teaming01-ReconNetwork Enumeration

Nmap - Network Enumeration

Cheatsheet

# Scan the full range rustscan -a 192.168.1.0/24 # Default scan with OS and service detection sudo rustscan -a 192.168.1.7 -- -A -oA results # Full TCP scan with service detection and default scripts sudo nmap <IP> -p- -sV -sC -oA full_tcp # Top 1000 ports sudo nmap <IP> -sS -Pn -n -oA quick # Aggressive scan sudo nmap <IP> -A -oA aggressive # UDP scan of the top 100 ports sudo nmap <IP> -sU -F -oA udp_fast # Host discovery on a subnet sudo nmap <NETWORK>/24 -sn -oA discovery # Host discovery from a file sudo nmap -sn -iL hosts.lst -oA discovery # NSE vulnerability scan on one port sudo nmap <IP> -p <PORT> -sV --script vuln -oA vuln_check # Firewall evasion with a decoy scan sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping -D RND:5 # Firewall evasion with source port 53 sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping --source-port 53 # Connect to a filtered port with source port 53 ncat -nv --source-port 53 <IP> <PORT> # Convert XML output to an HTML report xsltproc target.xml -o target.html

Methodology

Phase 1: Host Discovery

Ask yourself

  • Which hosts in the target scope are alive?
  • Do host firewalls block ICMP echo requests?
  • Are the targets on the same subnet? Use ARP ping.
  • Are the targets remote? Use ICMP or TCP probes.
  • Does a missing response mean the host is down?
  • Or did a filter drop the probes?
  • If ICMP fails, which other discovery methods should I try?
  • Sweep the network range. Use -sn to find live hosts.
  • Check ARP results on the same subnet. Nmap sends ARP pings automatically when targets are local.
  • Retry hosts that appear down. Use TCP SYN to common ports (-PS22,80,443) or TCP ACK (-PA80).
  • Scan targets from a list. Use -iL hosts.lst.
  • Save discovery results. Use -oA so you can compare methods.
  • Record which hosts responded. Non-responders may or may not need more investigation.
# Subnet sweep sudo nmap 10.129.2.0/24 -sn -oA tnet | grep for | cut -d" " -f5 # IP range shorthand sudo nmap -sn -oA tnet 10.129.2.18-20 # Force ICMP echo. Disable ARP on the local subnet. sudo nmap <IP> -sn -PE --disable-arp-ping --packet-trace # Use --reason to show why Nmap marks a host alive sudo nmap <IP> -sn -PE --reason

Phase 2: Port Scanning

Ask yourself

  • Should I start with a top-ports scan?
  • Or should I start with a full port scan?
  • Is a SYN scan (-sS) appropriate? It needs root.
  • Is a Connect scan (-sT) appropriate? It does not need root.
  • Do filtered ports show that a firewall is present?
  • How do I tell dropped packets (no response) from rejected packets (RST or ICMP)?
  • Did I scan UDP ports? Or only TCP?
  • What trade-off between speed and accuracy is acceptable for this engagement?
  • Run a fast first scan. Use -F or --top-ports=100/1000.
  • Start a full TCP port scan. Use -p- in the background.
  • Check filtered ports. Use --packet-trace and --reason. See if the target dropped or rejected the packets.
  • Run a UDP scan. Use -sU -F. Administrators often forget UDP filtering.
  • Record all port states. Record open, closed, filtered, and open|filtered.
  • If you have little time, set an order. Finish full TCP first. Then scan common UDP services (53, 67, 68, 69, 123, 137, 138, 161, 500, 514, 1900, 5353).
# SYN scan top 1000 (default, needs root) sudo nmap <IP> -sS -oA syn_scan # Connect scan nmap <IP> -sT -oA connect_scan # Full port range sudo nmap <IP> -p- -oA all_ports # Trace one port to observe firewall behavior sudo nmap <IP> -p <PORT> --packet-trace -Pn -n --disable-arp-ping # UDP scan top 100 sudo nmap <IP> -sU -F -oA udp_scan

Phase 3: Service Enumeration and Version Detection

Ask yourself

  • What exact service and version runs on each open port?
  • Does the banner match the Nmap signature result?
  • Is Nmap missing information that a manual banner grab would show?
  • What OS can I infer from service banners and TTL values?
  • Which services are candidates for known CVEs based on their version?
  • Fingerprint services. Run -sV on all open ports.
  • Grab banners manually. Use nc or ncat on unknown or interesting ports. Catch details that Nmap misses.
  • Run default scripts. Use -sC for extra enumeration that is safe.
  • Run an aggressive scan if noise is acceptable. -A combines -sV, -O, --traceroute, and -sC.
  • Compare automatic results with manual results. Nmap sometimes truncates banner data.
  • Record exact versions for exploit research.
# Service version detection sudo nmap <IP> -p- -sV -oA versions # Version detection and default scripts sudo nmap <IP> -p- -sV -sC -oA full_enum # Manual banner grab to check results ncat -nv <IP> <PORT> # Monitor progress on long scans sudo nmap <IP> -p- -sV --stats-every=5s

Phase 4: NSE Scripts and Vulnerability Assessment

Ask yourself

  • Which NSE script categories are safe to run without disrupting services?
  • Does the vuln category show known CVEs for the detected versions?
  • Are there scripts for this service that extract extra data?
  • Can those scripts list users, shares, or directories?
  • What is the OPSEC cost of running intrusive script categories?
  • Do script results match what I would expect from the identified version?
  • Scan high-value ports for known vulnerabilities. Use --script vuln.
  • Use scripts for the specific service. Example: banner,smtp-commands for SMTP.
  • Avoid brute, dos, exploit, and intrusive. Run them only when they are explicitly authorized and OPSEC-acceptable.
  • Compare CVEs from NSE with version data. Check that each CVE applies.
  • Record all script output for the report.
# Default safe scripts sudo nmap <IP> -p <PORT> -sC # Vulnerability scanning sudo nmap <IP> -p <PORT> -sV --script vuln # Specific scripts sudo nmap <IP> -p 25 --script banner,smtp-commands # Script category sudo nmap <IP> --script discovery

Phase 5: Firewall and IDS/IPS Evasion

Ask yourself

  • Does the firewall drop filtered ports (no response, long timeout)?
  • Or does it reject them (ICMP unreachable, RST, or ICMP error)?
  • Does an ACK scan (-sA) show unfiltered ports that a SYN scan shows as filtered?
  • Can I bypass firewall rules with source port 53 (DNS)?
  • Would decoys or fragmentation help evade IDS detection?
  • Is an IPS blocking my scanning IP?
  • If the target blocks me, should I switch IP or MAC address?
  • Compare SYN scan results with ACK scan results. Map firewall rules.
  • Test filtered ports with --source-port 53. Poorly configured firewalls trust DNS traffic.
  • Use decoy scans (-D RND:5). Hide the true source among other addresses.
  • Scan from a different source IP. Use -S <IP> -e <interface> to test subnet-based rules.
  • Fragment packets (-f). Evade shallow packet inspection.
  • Use --data-length <num>. Add data so packets match signatures less often.
  • If the target blocks a VPS, switch IP or MAC address. This shows an IPS is active.
  • Connect to newly found open ports. Use ncat --source-port 53 to check access.
# ACK scan to detect firewall rules sudo nmap <IP> -p 21,22,25 -sA -Pn -n --disable-arp-ping --packet-trace # Decoy scan with 5 random IPs sudo nmap <IP> -p 80 -sS -Pn -n --disable-arp-ping -D RND:5 # Source port 53 to bypass misconfigured firewalls sudo nmap <IP> -p <PORT> -sS -Pn -n --disable-arp-ping --source-port 53 # Spoof source IP. You must set the interface. sudo nmap <IP> -p <PORT> -O -S <SPOOFED_IP> -e tun0 # Check access to a filtered port with source port 53 ncat -nv --source-port 53 <IP> <PORT> # Specify DNS servers for queries sudo nmap <IP> --dns-server <NS1>,<NS2>

Phase 6: Performance Tuning

Ask yourself

  • Is scan speed causing me to miss hosts or ports (false negatives)?
  • Am I whitelisted, so I may use aggressive timing?
  • Or must I remain below IDS thresholds?
  • What is the network bandwidth and latency to the target?
  • Is the trade-off between -T4/-T5 speed and possible detection acceptable?
  • Should I reduce retries or adjust RTT timeouts for this network?
  • Speed scans in whitelisted or lab environments. Use -T4 or --min-rate 300.
  • For stealth, use -T2 or -T1. Accept longer scan times.
  • Set --initial-rtt-timeout and --max-rtt-timeout. Use values based on observed latency.
  • Reduce --max-retries (default 10) to increase speed. Accept that you may miss ports.
  • Always compare fast scans with default scans. Measure what speed costs.
# Aggressive timing sudo nmap <NETWORK>/24 -F -T4 # Insane timing (lab only) sudo nmap <NETWORK>/24 -F -T5 # Custom rate. Minimum 300 packets per second. sudo nmap <NETWORK>/24 -F --min-rate 300 # Reduced RTT for fast networks sudo nmap <NETWORK>/24 -F --initial-rtt-timeout 50ms --max-rtt-timeout 100ms # Zero retries. Fastest. May miss ports. sudo nmap <NETWORK>/24 -F --max-retries 0

When the Scan Finds Nothing

Ask yourself

  • Did I scan all 65535 TCP ports (-p-)?
  • Or did I stop at the top 1000?
  • Did I skip UDP? Many footholds (SNMP, TFTP, DNS, IKE) use UDP only.
  • Does the host look down only because it blocks ICMP?
  • Did I try -Pn?
  • Can aggressive timing or low retries cause false negatives?
  • Could a firewall drop my SYN packets when another technique would succeed?
  • Re-run with -p- -Pn. Force a full scan even if the host looks down.
  • Add a UDP scan if you only ran TCP.
  • Reduce speed. Use -T2 and default retries. Compare against the fast baseline.
  • Try other techniques. Use -sT (no root), -sA (firewall mapping), or --source-port 53.
  • Switch source IP or VPS if an IPS may have blocked you.
  • Check reachability outside Nmap. Use ping, nc, and traceroute before you assume the host is offline.

OPSEC

Port scanning is noisy. Assume a competent defender can see it. Pick the technique that matches your noise budget.

TechniqueNoiseTelemetry a defender sees
SYN scan (-sS)MediumMany half-open connections. IDS signatures (for example Snort or Suricata portscan). Firewall logs.
Connect scan (-sT)HighCompleted connections in service logs (auth logs, web logs). Netflow.
Aggressive (-A)HighVersion probes, OS fingerprint packets, NSE traffic, and traceroute. This traffic is very distinctive.
UDP scan (-sU)MediumBursts of empty datagrams. Slow, sustained traffic that lingers in logs.
vuln/brute NSEHigh–CriticalExploit or login attempts. May appear as attacks and trigger blocks.
Decoy (-D)MediumHides the source among spoofed IPs. Volume still flags a portscan.
-T0/-T1LowSpreads probes over time to remain below IDS thresholds. Costs hours.

OPSEC. Noise: medium-high. Telemetry: IDS portscan alerts, firewall deny logs, service connection logs, and netflow. Prerequisite: root for -sS, -sU, and -O. Footprint: connection log entries. No persistent change on the target.

Reference

Nmap Architecture

Nmap divides into five core capabilities:

  1. Host discovery. Determine which targets are alive.
  2. Port scanning. Identify open, closed, and filtered ports.
  3. Service enumeration. Fingerprint services and versions.
  4. OS detection. Identify the operating system.
  5. NSE. Scriptable interaction with target services.

Syntax

nmap <scan types> <options> <target>

Scan Techniques

FlagTechniqueUse Case
-sSTCP SYN (half-open)Default with root. Stealthier than Connect.
-sTTCP Connect (full handshake)No root required. Creates logs on the target.
-sATCP ACKFirewall rule mapping (not port state).
-sUUDPStateless. Slow. Administrators often forget it.
-sN/-sF/-sXTCP Null/FIN/XmasFirewall evasion. Unreliable on Windows.
-sWTCP WindowLike ACK, but inspects the RST window field.
-sIIdle scanFully blind via a zombie host.
-sOIP protocol scanIdentify supported IP protocols.

Port States

StateMeaning
openConnection established (SYN-ACK for TCP, response for UDP).
closedRST received. The port is reachable, but no service is listening.
filteredNo response or ICMP error. A firewall is likely dropping or rejecting traffic.
unfilteredACK scan only. The port is reachable, but open or closed is unknown.
open|filteredNo response on UDP, Null, FIN, or Xmas. Ambiguous.
closed|filteredIdle scan only. Cannot determine state.

TCP SYN Scan Behavior

  • Sends SYN → receives SYN-ACK = open
  • Sends SYN → receives RST = closed
  • Sends SYN → no response after retries = filtered

Nmap never completes the three-way handshake. Most services do not log a full TCP connection. Advanced IDS or IPS can still detect half-open scans.

TCP Connect Scan Behavior

A Connect scan completes the full three-way handshake. It is more accurate. It also creates connection logs. It behaves like a normal client. That makes it less likely to crash fragile services.

UDP Scan Behavior

  • Sends empty datagram → receives UDP response = open
  • Sends empty datagram → receives ICMP port unreachable (type 3, code 3) = closed
  • Sends empty datagram → no response after retries = open|filtered

UDP scanning is slower than TCP. UDP has no acknowledgment. Timeouts are longer.

OS Detection

-O fingerprints the operating system from TCP/IP stack behavior. It uses packet order, initial sequence numbers, TCP options, and window sizes. It needs root. It is most accurate with at least one open port and one closed port.

# Standalone OS detection sudo nmap <IP> -O # More aggressive guessing when there is no exact match sudo nmap <IP> -O --osscan-guess

When Nmap cannot find an exact match, it prints percentage-based Aggressive OS guesses. Treat these as hints, not facts. Compare them with reply TTL values and service banners. Approximate TTL values: 64 for Linux or Unix, 128 for Windows, 255 for network gear. OS detection packets are distinctive. Defenders can flag them easily. Run OS detection only when the noise is acceptable.

NSE Script Categories

CategoryDescriptionOPSEC Risk
authAuthentication credential checksLow
broadcastHost discovery via broadcastMedium
bruteBrute-force login attemptsHigh
defaultSafe scripts run with -sCLow
discoveryService and network information gatheringLow
dosDenial-of-service testingCritical
exploitActive exploitation of known vulnerabilitiesCritical
externalQueries external services (for example whois)Low
fuzzerProtocol fuzzingHigh
intrusiveMay crash or disrupt servicesHigh
malwareMalware infection checksLow
safeNon-intrusive, non-destructiveLow
versionExtended version detectionLow
vulnVulnerability identificationMedium

Output Formats

FlagFormatExtensionUse
-oNNormal text.nmapHuman-readable
-oGGrepable.gnmapQuick parsing with grep/awk
-oXXML.xmlTool integration, HTML reports
-oAAll threeallAlways use this

Convert XML to HTML: xsltproc target.xml -o target.html

Timing Templates

TemplateNameUse Case
-T0ParanoidIDS evasion. Serialized. 5-minute wait between probes.
-T1SneakyIDS evasion. 15-second interval.
-T2PoliteReduced bandwidth usage.
-T3NormalDefault.
-T4AggressiveFast. Reliable networks.
-T5InsaneLab or whitelisted only. May miss ports.

Performance Tuning Options

OptionEffectTrade-off
--min-rate <n>Minimum packets per secondMay overwhelm slow links
--max-retries <n>Retry limit per port (default 10)Lower is faster but may miss
--initial-rtt-timeout <ms>Starting RTT estimateToo low causes false negatives
--max-rtt-timeout <ms>Maximum wait for a responseToo low misses slow hosts
--host-timeout <time>Stop scanning a host after this timeSkips unresponsive targets
--min-parallelism <n>Minimum parallel probesHigher is faster and noisier

Firewall Evasion Techniques

TechniqueFlagHow It Works
Decoy scan-D RND:5Inserts fake source IPs among real scan packets
Source port spoof--source-port 53Uses a trusted port (DNS) as the source
Source IP spoof-S <IP> -e <iface>Changes the source IP. Responses must route back.
Fragmentation-fSplits packets into 8-byte fragments
MTU control--mtu <size>Custom fragment size (must be a multiple of 8)
Data length--data-length <n>Appends random data to change the packet signature
DNS servers--dns-server <ns>Use internal DNS servers for resolution
Idle scan-sI <zombie>Fully blind scan via the IPID of a zombie host

ACK Scan for Firewall Mapping

The ACK scan (-sA) cannot determine if a port is open or closed. It determines whether a firewall filters or does not filter the port:

  • RST response = unfiltered (the firewall allows the packet through)
  • No response / ICMP error = filtered (the firewall blocks it)

Compare -sS and -sA results. Identify which ports the firewall protects.

Nmap -sV can miss details from service banners. Check banners manually:

# Manual banner grab nc -nv <IP> <PORT> # Capture the three-way handshake and banner with tcpdump sudo tcpdump -i eth0 host <LHOST> and <IP>

The PSH-ACK packet after the handshake often contains the full banner. That banner may include OS distribution details that Nmap may truncate.

Service banners can be customized or stripped. Never rely only on banner data for OS or version identification. Compare banners with other evidence. Use TTL values, TCP window sizes, and protocol behavior.

Key Differences: Dropped vs. Rejected Packets

BehaviorIndicatorWhat It Means
DroppedNo response. The scan takes about 2 seconds per port because of retransmissions.The firewall discards packets with no reply.
RejectedICMP type 3/code 3 or TCP RST. Fast response.The firewall denies the packet and notifies the sender.

Rejected packets show a firewall immediately. Dropped packets waste attacker time. Dropped packets also show filtering if you compare timing.

Knowledge Check

Quiz

Your default Nmap scan of a host returns: Host seems down. If it is really up, but blocking our ping probes, try -Pn. The host is in scope. Other hosts on the subnet respond. What is the best next step?

Quiz

A SYN scan shows TCP/445 as filtered. You need to know whether a firewall is dropping or rejecting the traffic. You also need to know whether any rule lets packets through. Which single technique most directly maps the firewall's behavior?

Quiz

You are scanning a target on a monitored corporate network. You must remain below the IDS radar and still discover services. Which approach best balances stealth with results?

Common Mistakes

Frequent errors

  • Run only TCP scans and forget UDP. Critical services (DNS, SNMP, TFTP, NFS) live on UDP.
  • Use -T5 on real engagements. This triggers IDS or IPS. You may also miss filtered ports.
  • Set --max-retries 0 or aggressive RTT timeouts. Do this without a baseline comparison.
  • Assume “filtered” means “protected.” It means a firewall is present. Bypass paths may still exist.
  • Skip -oA. Comparison and reporting become hard later.
  • Trust Nmap version detection without a manual banner check.
  • Scan without -Pn when targets block ICMP. Nmap marks hosts as down and skips them.
  • Forget --source-port 53 on filtered ports. Misconfigured firewalls often trust DNS.

#Penetration-Testing #HTB #Nmap #NetworkEnum #PortScan #ServiceDetection #Recon #RustScan #Firewall-Evasion #Linux #Windows #RedTeam #Certification

Last updated on