Skip to content
Authors: fire1ce | Created: 2021-08-27 | Last update: 2022-08-02

Nmap CheatSheet

Common Nmap Commands

Aggressive scan, single host, TCP SYN, :

nmap -n -sS -p- -T4 -Pn -A -v

Ping Scan - Host discovery in subnet

nmap -sn -v

Target Specification

Switch Description Example
nmap Scan a single IP
nmap Scan specific IPs
nmap Scan a range
nmap Scan a domain
nmap Scan using CIDR notation
-iL nmap -iL targets.txt Scan targets from a file
-iR nmap -iR 100 Scan 100 random hosts
--exclude nmap --exclude Exclude listed hosts

Scan Techniques

Switch Example Description
-sS nmap -sS TCP SYN port scan (Default)
-sT nmap -sT TCP connect port scan (Default without root privilege)
-sU nmap -sU UDP port scan
-sA nmap -sA TCP ACK port scan
-sW nmap -sW TCP Window port scan
-sM nmap -sM TCP Maimon port scan

Host Discovery

Switch Description Example
-sL nmap -sL No Scan. List targets only
-sn nmap -sn Disable port scanning. Host discovery only.
-Pn nmap -Pn Disable host discovery. Port scan only.
-PS nmap -PS22-25,80 TCP SYN discovery on port x.Port 80 by default
-PA nmap -PA22-25,80 TCP ACK discovery on port x.Port 80 by default
-PU nmap -PU53 UDP discovery on port x.Port 40125 by default
-PR nmap -PR ARP discovery on local network
-n nmap -n Never do DNS resolution

Port Specification

Switch Description Example
-p nmap -p 21 Port scan for port x
-p nmap -p 21-100 Port range
-p nmap -p U:53,T:21-25,80 Port scan multiple TCP and UDP ports
-p nmap -p- Port scan all ports
-p nmap -p http,https Port scan from service name
-F nmap -F Fast port scan (100 ports)
--top-ports nmap --top-ports 2000 Port scan the top x ports
-p-65535 nmap -p-65535 Leaving off initial port in range makes the scan start at port 1
-p0- nmap -p0- Leaving off end port in rangemakes the scan go through to port 65535

Service and Version Detection

Switch Description Example
-sV nmap -sV Attempts to determine the version of the service running on port
-sV --version-intensity nmap -sV --version-intensity 8 Intensity level 0 to 9. Higher number increases possibility of correctness
-sV --version-light nmap -sV --version-light Enable light mode. Lower possibility of correctness. Faster
-sV --version-all nmap -sV --version-all Enable intensity level 9. Higher possibility of correctness. Slower
-A nmap -A Enables OS detection, version detection, script scanning, and traceroute

OS Detection

Switch Description Example
-O nmap -O Remote OS detection using TCP/IP stack fingerprinting
-O --osscan-limit nmap -O --osscan-limit If at least one open and one closed TCP port are not found it will not try OS detection against host
-O --osscan-guess nmap -O --osscan-guess Makes Nmap guess more aggressively
-O --max-os-tries nmap -O --max-os-tries 1 Set the maximum number x of OS detection tries against a target
-A nmap -A Enables OS detection, version detection, script scanning, and traceroute

Timing and Performance

Switch Description Example
-T0 nmap -T0 Paranoid (0) Intrusion DetectionSystem evasion
-T1 nmap -T1 Sneaky (1) Intrusion Detection Systemevasion
-T2 nmap -T2 Polite (2) slows down the scan to useless bandwidth and use less target machine resources
-T3 nmap -T3 Normal (3) which is default speed
-T4 nmap -T4 Aggressive (4) speeds scans; assumes you are on a reasonably fast and reliable network
-T5 nmap -T5 Insane (5) speeds scan; assumes you are on an extraordinarily fast network
-------- -------- -------------------------------------------------------------------------------------------
--host-timeout 1s; 4m; 2h Give up on target after this long
--min-rtt-timeout/max-rtt-timeout/initial-rtt-timeout 1s; 4m; 2h Specifies probe round trip time
--min-hostgroup/max-hostgroup <size 50; 1024 Parallel host scan group sizes
--min-parallelism/max-parallelism 10; 1 Probe parallelization
--scan-delay/--max-scan-delay 20ms; 2s; 4m; 5h Adjust delay between probes
--max-retries 3 Specify the maximum number of port scan probe retransmissions
--min-rate 100 Send packets no slower than per second
--max-rate 100 Send packets no faster than per second

NSE Scripts

Switch Description Example
-sC nmap -sC Scan with default NSE scripts. Considered useful for discovery and safe
--script default nmap --script default Scan with default NSE scripts. Considered useful for discovery and safe
--script nmap --script=banner Scan with a single script. Example banner
--script nmap --script=http* Scan with a wildcard. Example http
--script nmap --script=http,banner Scan with two scripts. Example http and banner
--script nmap --script "not intrusive" Scan default, but remove intrusive scripts
--script-args nmap --script snmp-sysdescr --script-args snmpcommunity=admin NSE script with arguments

Useful NSE Script Examples

Command Description
nmap -Pn --script=http-sitemap-generator http site map generator
nmap -n -Pn -p 80 --open -sV -vvv --script banner,http-title -iR 1000 Fast search for random web servers
nmap -Pn --script=dns-brute Brute forces DNS hostnames guessing subdomains
nmap -n -Pn -vv -O -sV --script smb-enum,smb-ls,smb-mbenum,smb-os-discovery,smb-s,smb-vuln,smbv2 -vv Safe SMB scripts to run
nmap --script whois* Whois query
nmap -p80 --script http-unsafe-output-escaping Detect cross site scripting vulnerabilities
nmap -p80 --script http-sql-injection Check for SQL injections

Firewall / IDS Evasion and Spoofing

Switch Description Example
-f nmap -f Requested scan (including ping scans) use tiny fragmented IP packets. Harder for packet filters
--mtu nmap --mtu 32 Set your own offset size
-D nmap -D,,, Send scans from spoofed IPs
-D nmap -D decoy-ip1,decoy-ip2,your-own-ip,decoy-ip3,decoy-ip4 remote-host-ip Above example explained
-S nmap -S Scan Facebook from Microsoft (-e eth0 -Pn may be required)
-g nmap -g 53 Use given source port number
--proxies nmap --proxies, Relay connections through HTTP/SOCKS4 proxies
--data-length nmap --data-length 200 Appends random data to sent packets

Example IDS Evasion command

nmap -f -t 0 -n -Pn –data-length 200 -D,,,


Switch Description Example
-oN nmap -oN normal.file Normal output to the file normal.file
-oX nmap -oX xml.file XML output to the file xml.file
-oG nmap -oG grep.file Grepable output to the file grep.file
-oA nmap -oA results Output in the three major formats at once
-oG - nmap -oG - Grepable output to screen. -oN -, -oX - also usable
--append-output nmap -oN file.file --append-output Append a scan to a previous scan file
-v nmap -v Increase the verbosity level (use -vv or more for greater effect)
-d nmap -d Increase debugging level (use -dd or more for greater effect)
--reason nmap --reason Display the reason a port is in a particular state, same output as -vv
--open nmap --open Only show open (or possibly open) ports
--packet-trace nmap -T4 --packet-trace Show all packets sent and received
--iflist nmap --iflist Shows the host interfaces and routes
--resume nmap --resume results.file Resume a scan

Helpful Nmap Output examples

Scan for web servers and grep to show which IPs are running web servers

nmap -p80 -sV -oG - --open | grep open

Generate a list of the IPs of live hosts

nmap -iR 10 -n -oX out.xml | grep "Nmap" | cut -d " " -f5 > live-hosts.txt

Append IP to the list of live hosts

nmap -iR 10 -n -oX out2.xml | grep "Nmap" | cut -d " " -f5 >> live-hosts.txt

Compare output from nmap using the ndif

ndiff scanl.xml scan2.xml

Convert nmap xml files to html files

xsltproc nmap.xml -o nmap.html

Reverse sorted list of how often ports turn up

grep " open " results.nmap | sed -r 's/ +/ /g' | sort | uniq -c | sort -rn | less

Miscellaneous Options

Switch Description Example
-6 nmap -6 2607:f0d0:1002:51::4 Enable IPv6 scanning
-h nmap -h nmap help screen

Other Useful Nmap Commands

Discovery only on ports x, no port scan

nmap -iR 10 -PS22-25,80,113,1050,35000 -v -sn

Arp discovery only on local network, no port scan

nmap -PR -sn -vv

Traceroute to random targets, no port scan

nmap -iR 10 -sn -traceroute

Query the Internal DNS for hosts, list targets only

nmap -sL --dns-server