Nmap
Nmap (Network Mapper) is a network scanning and security auditing tool used to discover devices on a network and identify the open ports, running services, service versions, and sometimes the operating system of those devices.
Think of Nmap like a security inspector for a network.
For example, imagine a server is a house:
SERVER
┌──────────────┐
│ │
Port 22 ──►│ SSH │
Port 80 ──►│ Web Server │
Port 443 ──►│ HTTPS │
Port 3306 ─►│ MySQL │
│ │
└──────────────┘
Nmap checks these network "doors" and tells you which ones are accessible.
What Nmap can tell you
Target
↓
Is the device online?
↓
Which ports are open?
↓
Which services are running?
↓
What software/version is running?
↓
What OS might be running?
↓
Are there security-related findings that Nmap's scripts can detect?
Simple real-life example
Suppose you have a server:
192.168.1.10
You run:
nmap 192.168.1.10
You might get:
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
3306/tcp closed mysql
This means:
22 open → SSH service is accessible
80 open → HTTP web service is accessible
443 open → HTTPS web service is accessible
3306 closed → MySQL isn't accepting connections on that port
Why cybersecurity professionals use Nmap
Nmap is commonly used during the reconnaissance and enumeration stages of security testing.
It helps answer:
"What is exposed on this network?"
Security professionals can use that information to identify unnecessary or unexpected services and investigate whether they need to be secured.
Important point
Nmap does not automatically mean hacking.
It is a legitimate security and administration tool. You should scan systems you own or have explicit permission to test.
One-line definition for your notes
Nmap is an open-source network discovery and security auditing tool used to discover hosts, scan ports, identify services and versions, perform OS detection, and conduct various network security checks.
Linux · Window