CyberNotes

Reconnaissance & OSINT

Nmap

Reconnaissance & OSINTLinuxWindow

Nmap (Network Mapper) is a network scanning and security auditing tool used to discover devices on a network and identify the open ports, running services, service versions, and sometimes the operating system of those devices.

Think of Nmap like a security inspector for a network.

For example, imagine a server is a house:

             SERVER
        ┌──────────────┐
        │              │

Port 22 ──►│ SSH │ Port 80 ──►│ Web Server │ Port 443 ──►│ HTTPS │ Port 3306 ─►│ MySQL │ │ │ └──────────────┘ Nmap checks these network "doors" and tells you which ones are accessible.

What Nmap can tell you Target ↓ Is the device online? ↓ Which ports are open? ↓ Which services are running? ↓ What software/version is running? ↓ What OS might be running? ↓ Are there security-related findings that Nmap's scripts can detect? Simple real-life example

Suppose you have a server:

192.168.1.10

You run:

nmap 192.168.1.10

You might get:

PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https 3306/tcp closed mysql

This means:

22 open → SSH service is accessible 80 open → HTTP web service is accessible 443 open → HTTPS web service is accessible 3306 closed → MySQL isn't accepting connections on that port Why cybersecurity professionals use Nmap

Nmap is commonly used during the reconnaissance and enumeration stages of security testing.

It helps answer:

"What is exposed on this network?"

Security professionals can use that information to identify unnecessary or unexpected services and investigate whether they need to be secured.

Important point

Nmap does not automatically mean hacking.

It is a legitimate security and administration tool. You should scan systems you own or have explicit permission to test.

One-line definition for your notes

Nmap is an open-source network discovery and security auditing tool used to discover hosts, scan ports, identify services and versions, perform OS detection, and conduct various network security checks.

Installation

Nmap Installation Commands

  1. Linux (Kali Linux / Ubuntu / Debian)

Open the Terminal and run:

Step 1: Update package list sudo apt update Step 2: Install Nmap sudo apt install nmap -y Step 3: Verify installation nmap --version

If installed successfully, it will display the Nmap version and other information.

  1. Windows 10 / 11 Method 1: Using PowerShell (recommended)

Open PowerShell as Administrator and run:

winget install Insecure.Nmap

After installation, verify it:

nmap --version

If winget is unavailable, use the official installer.

Method 2: Official Windows Installer

Open the official Nmap download page: https://nmap.org/download.html

Download the Windows installer.

Run the .exe file.

Follow the installation wizard.

Open PowerShell or Command Prompt.

Verify the installation:

nmap --version

Note: The Windows installer includes Npcap, which supports the packet-capture and raw-networking features used by Nmap.

Basic Usage

Nmap Basic Usage

The easiest way to understand Nmap is:

Nmap command = What you want to scan + Where you want to scan

Basic structure:

nmap [options] <target>

For example:

nmap 192.168.1.10

Here 192.168.1.10 is the target.

  1. Check if Nmap is installed nmap --version

or:

nmap -V 2. Basic Scan nmap 192.168.1.10

This performs a basic scan of the target.

Example output:

PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https

Understand it as:

22 → Port number tcp → Protocol open → Port is accepting connections ssh → Service associated with the port 3. Scan Your Own Computer

For learning, start with your own machine:

nmap localhost

You can also use:

nmap 127.0.0.1

Both refer to your local computer.

  1. Scan a Specific Port

If you only want to check port 80:

nmap -p 80 192.168.1.10

Multiple ports:

nmap -p 22,80,443 192.168.1.10

Port range:

nmap -p 1-1000 192.168.1.10 Remember -p = port 5. Scan All TCP Ports

By default, Nmap doesn't necessarily scan every possible port.

To scan all TCP ports:

nmap -p- 192.168.1.10

-p- means:

Port 1 → 65535

This can take longer than a basic scan.

  1. Find Devices on Your Network

Suppose your local network is:

192.168.1.0/24

You can perform host discovery:

nmap -sn 192.168.1.0/24

-sn means host discovery without a port scan.

Example:

Nmap scan report for 192.168.1.1 Host is up

Nmap scan report for 192.168.1.5 Host is up

Nmap scan report for 192.168.1.10 Host is up

So you can think:

-sn ↓ "Which devices are alive?" 7. Detect Service Versions

Use:

nmap -sV 192.168.1.10

Instead of only:

80/tcp open http

you may get information such as:

80/tcp open http Apache httpd 443/tcp open https nginx

-sV means service/version detection.

This is very useful for cybersecurity because knowing what software is exposed helps you assess the attack surface.

  1. Detect Operating System nmap -O 192.168.1.10

-O means OS detection.

Nmap attempts to determine the operating system from network characteristics.

Example:

OS details: Linux

This is an OS fingerprint/guess, so it isn't guaranteed to be correct.

  1. TCP SYN Scan

One of the most commonly discussed Nmap scan types:

sudo nmap -sS 192.168.1.10

-sS = TCP SYN scan

Conceptually:

Nmap | | SYN ↓ Target | | SYN/ACK ↓ Nmap | └── Port appears OPEN

On systems where raw packet privileges are required, you may need sudo.

  1. UDP Scan

To scan UDP ports:

sudo nmap -sU 192.168.1.10

-sU = UDP scan

UDP is used by services such as DNS and SNMP, so UDP scanning can reveal services that a TCP-only scan won't.

  1. Aggressive Scan

You may see this command frequently:

sudo nmap -A 192.168.1.10

-A enables several advanced detection capabilities together, including:

OS detection Version detection NSE scripting Traceroute

For beginners, it's better to learn the individual options (-sV, -O, etc.) first.

  1. Run Nmap Scripts

Nmap has the Nmap Scripting Engine (NSE).

Example:

nmap --script <script-name> 192.168.1.10

NSE can perform various discovery, enumeration, and security checks.

Don't blindly run scripts against systems you don't own or have permission to test.

  1. Save Scan Results

Save normal output:

nmap -oN scan.txt 192.168.1.10

Save XML:

nmap -oX scan.xml 192.168.1.10

This is useful when you want to keep a record of your assessment.

  1. Scan Multiple Targets

You can scan multiple IP addresses:

nmap 192.168.1.10 192.168.1.20 192.168.1.30

Or a range:

nmap 192.168.1.10-20 15. Basic Commands You Should Memorize Command Purpose nmap <IP> Basic scan nmap localhost Scan your own machine nmap -p 80 <IP> Scan port 80 nmap -p 22,80,443 <IP> Scan selected ports nmap -p 1-1000 <IP> Scan port range nmap -p- <IP> Scan all TCP ports nmap -sn <network> Discover active hosts nmap -sV <IP> Detect services/versions nmap -O <IP> OS detection nmap -sS <IP> TCP SYN scan nmap -sU <IP> UDP scan nmap -A <IP> Advanced/aggressive scan nmap --script <name> <IP> Run NSE script nmap -oN file.txt <IP> Save results 🧠 Easy way to remember

Think of Nmap in this order:

          NMAP
            │
   ┌────────┴────────┐
   ↓                 ↓

DISCOVERY SCANNING │ │ ↓ ↓ Who is online? Which ports? │ ↓ Which service? │ ↓ Which version? │ ↓ Which OS? Start your practice with only these 5: nmap localhost nmap -p 80 localhost nmap -sV localhost nmap -O localhost nmap -p- localhost

Note : Use your own machine or an authorized lab while practicing.

Common Commands

Nmap Common Commands Cheat Sheet

Here are the most commonly used Nmap commands you should know first.

🔹 Basic Scanning nmap 192.168.1.10

Basic scan of a target.

nmap localhost

Scan your own computer.

nmap 192.168.1.10-20

Scan a range of IP addresses.

nmap 192.168.1.0/24

Scan an entire subnet.

🔹 Host Discovery nmap -sn 192.168.1.0/24

Find which devices are online without performing a normal port scan.

-sn → Host discovery 🔹 Port Scanning nmap -p 80 192.168.1.10

Scan a specific port.

nmap -p 22,80,443 192.168.1.10

Scan multiple ports.

nmap -p 1-1000 192.168.1.10

Scan ports 1–1000.

nmap -p- 192.168.1.10

Scan all TCP ports (1–65535).

🔹 Service Detection nmap -sV 192.168.1.10

Detect the service and version running on open ports.

Example:

80/tcp open http Apache httpd 443/tcp open https nginx 🔹 Operating System Detection sudo nmap -O 192.168.1.10

Attempts to identify the target's operating system.

-O → OS detection 🔹 TCP SYN Scan sudo nmap -sS 192.168.1.10

Common TCP scanning technique.

-sS → SYN scan 🔹 UDP Scan sudo nmap -sU 192.168.1.10

Scans UDP ports.

-sU → UDP scan 🔹 Aggressive Scan sudo nmap -A 192.168.1.10

Enables several advanced detection features such as:

OS detection Service/version detection NSE scripts Traceroute 🔹 NSE Scripts nmap --script <script-name> 192.168.1.10

Runs an Nmap Scripting Engine script.

For example, for basic HTTP enumeration in an authorized lab:

nmap --script http-title 192.168.1.10 🔹 Firewall/Filtering Information sudo nmap -sA 192.168.1.10

Performs an ACK scan that can help investigate packet filtering behavior.

🔹 Traceroute nmap --traceroute 192.168.1.10

Attempts to show the network path to the target.

🔹 Save Results nmap -oN scan.txt 192.168.1.10

Save normal output to a text file.

nmap -oX scan.xml 192.168.1.10

Save results in XML format.

⭐ Commands to Memorize First

If you're a beginner, don't try to memorize everything. Start with these:

Command Meaning nmap <IP> Basic scan nmap -sn <network> Find active devices nmap -p <port> <IP> Scan specific port nmap -p- <IP> Scan all TCP ports nmap -sV <IP> Detect service/version nmap -O <IP> OS detection nmap -sS <IP> SYN scan nmap -sU <IP> UDP scan nmap -A <IP> Advanced scan nmap --script <name> <IP> NSE script nmap -oN file.txt <IP> Save output 🧠 Easy memory trick -sS → SYN -sU → UDP -sV → Version -O → OS -A → Advanced -sn → Network/Host discovery -p → Port -oN → Normal output

For your cybersecurity notes, these are the core Nmap commands worth learning first.

Defensive / Authorized-Use Notes

Nmap — Defensive Security Notes

Nmap is not only a penetration-testing tool. From a defensive/security perspective, it can help administrators understand what is exposed on their network and identify services that may need to be secured.

  1. Defensive Purpose

The main defensive question is:

"What can an attacker see or reach from the network?"

Nmap can help security teams discover:

Active devices Open ports Running services Service versions Unexpected network exposure Potentially unnecessary services Network filtering behavior 2. Defensive Workflow Network ↓ Discover Devices ↓ Scan Open Ports ↓ Identify Services ↓ Identify Versions ↓ Review Exposure ↓ Reduce Unnecessary Exposure ↓ Rescan & Monitor 3. Common Defensive Commands Discover active hosts nmap -sn 192.168.1.0/24

Purpose: Identify devices that are responding on the network.

Check exposed ports nmap 192.168.1.10

Purpose: Find commonly exposed TCP services.

Check all TCP ports nmap -p- 192.168.1.10

Purpose: Find services that may be running on less-common ports.

Identify services and versions nmap -sV 192.168.1.10

Purpose: Determine what software/services are exposed.

Example:

22/tcp open ssh 80/tcp open http 443/tcp open https Check OS information sudo nmap -O 192.168.1.10

Purpose: Help identify the target's operating-system fingerprint.

  1. What Should a Defender Look For?

Suppose Nmap reports:

PORT STATE SERVICE 21/tcp open ftp 22/tcp open ssh 23/tcp open telnet 80/tcp open http 3306/tcp open mysql

A defender should ask:

Finding Defensive question FTP open Is FTP actually required? SSH open Should SSH be externally accessible? Telnet open Can this insecure legacy service be disabled? HTTP open Is unencrypted HTTP required or should HTTPS be used? MySQL open Does the database really need network exposure?

Important: An open port isn't automatically a vulnerability. The security concern depends on the service, configuration, exposure, authentication, patch level, and network context.

  1. Attack Surface

Nmap is useful for understanding the network attack surface.

             Server
                │
   ┌────────────┼────────────┐
   ↓            ↓            ↓
  SSH          HTTP         MySQL
   │            │            │
  22            80          3306
   │            │            │
   └────────────┴────────────┘
            Exposure

The more unnecessary services that are reachable, the more things an organization needs to secure and monitor.

  1. Defensive Actions After Finding an Open Port

Finding an unexpected port is only the beginning.

Open Port Found ↓ Identify Service ↓ Is it required? ↙ ↘ NO YES ↓ ↓ Disable Secure service service ↓ ↓ Firewall Patch rule Configure ↓ ↓ Rescan

Possible defensive actions:

Disable unnecessary services Apply security patches Restrict access with firewalls Use network segmentation Restrict administrative services to trusted networks Require strong authentication Remove obsolete protocols Monitor exposed services Repeat scans periodically 7. Nmap + Firewall

Nmap can help verify whether firewall rules are producing the intended exposure.

For example, your policy might be:

Internet ↓ Firewall ↓ Web Server ├── 80 → allowed ├── 443 → allowed └── 3306 → should NOT be publicly accessible

An authorized Nmap scan can help verify the intended result.

  1. Nmap + Vulnerability Management

Nmap can provide information that becomes useful for vulnerability management:

Nmap ↓ Open Port ↓ Service ↓ Version ↓ Asset Inventory ↓ Vulnerability Assessment ↓ Remediation

For example:

443/tcp → HTTPS → Web server → Version identified

The security team can then determine whether that software version requires updating.

Nmap itself should not be treated as a complete vulnerability-management platform.

  1. Defensive Monitoring

A security team can perform authorized scans periodically:

Monday ↓ Nmap scan ↓ Compare with previous scan ↓ New port? ↓ New service? ↓ Unexpected device? ↓ Investigate

This helps identify changes in network exposure.

Tools such as Ndiff can be used to compare Nmap scan results.

  1. Blue Team Perspective Red Team asks:

"What can I discover?"

Blue Team asks:

"What is exposed that shouldn't be exposed?"

          NMAP
            │
    ┌───────┴───────┐
    ↓               ↓
 Red Team         Blue Team
    ↓               ↓

Discover attack Discover & surface reduce exposure

The same tool can therefore be useful to both offensive and defensive security teams.

  1. Defensive Nmap Checklist

When scanning an authorized environment, review:

☐ What devices are active? ☐ Which ports are open? ☐ Which services are running? ☐ Are any unexpected services exposed? ☐ Are unnecessary services running? ☐ Are administrative services restricted? ☐ Are databases exposed unnecessarily? ☐ Are legacy protocols enabled? ☐ Are services patched? ☐ Are firewall rules working as intended? ☐ Has the exposure changed since the last scan? ⭐ One-line defensive definition

Nmap is a network discovery and security auditing tool that defenders can use to identify assets, exposed ports and services, understand network attack surface, verify security controls, and detect unexpected network exposure.

Best defensive mindset: Don't ask "How do I attack this open port?" first. Ask "Why is this port exposed, is it required, who should access it, and how can it be securely configured?"

Official documentation →

← Back to Tools Directory