Recon Nmap Public Source License Linux, macOS, Windows

nmap

Port, service and version scanner for mapping what a host exposes.

>_ Official sitenmap.org Visit

Nmap is a port scanner that maps what a host exposes on the network: which ports are open, what service is listening on each, and often the exact version. It is usually the first tool you run against a target, because a clear list of open ports tells you where to look next. This page takes you from a clean install to the handful of commands you will use on almost every scan.

Scope

Use it only on systems you own or are authorized to test.

Installing Nmap

Nmap ships in every major package manager, so installation is a single command on most systems. On Windows the signed installer also sets up the Npcap driver that Nmap needs to send raw packets.

bash
sudo apt install nmap        # Debian, Ubuntu, Kali
sudo dnf install nmap        # Fedora, RHEL, Rocky
brew install nmap            # macOS
bash
# Windows: download and run the installer from nmap.org/download.html
nmap --version               # confirm the install on any platform

Your first scan

The simplest useful scan names a target and lets Nmap check the most common ports. Run it against scanme.nmap.org, a host the Nmap project keeps online for exactly this kind of practice.

nmap scanme.nmap.org
$ nmap scanme.nmap.org
PORT     STATE  SERVICE
22/tcp   open   ssh
80/tcp   open   http
9929/tcp open   nping-echo

Each line is a port. STATE open means something is listening and accepting connections, closed means the port answered but nothing is there, and filtered means a firewall dropped the probe so Nmap could not tell. The SERVICE column is Nmap best guess from the port number, which the next step confirms.

Naming ports and targets

By default Nmap checks the 1000 most common ports. The -p flag changes that to a list, a range, or every port, and you can aim at one host or a whole subnet in the same command.

bash
nmap -p 80,443 example-host        # just these two ports
nmap -p 1-1000 example-host        # a range of ports
nmap -p- example-host              # all 65535 ports
nmap 192.168.1.0/24                # every host in a subnet

Service and version detection

Knowing a port is open is only the start; the next question is what is running on it. The -sV flag reads banners to identify the service and version, -sC adds a set of safe scripts, and -A turns on everything at once for a lab.

bash
nmap -sV example-host              # identify service versions
nmap -sV -sC example-host          # add the default NSE scripts
nmap -A example-host               # version, OS, scripts and traceroute
FlagWhat it does
-sVDetect the service and version on each open port
-sCRun the default set of safe NSE scripts
-pChoose ports: a list, a range, or -p- for all
-PnSkip the ping check and scan a host that blocks ping
-AAggressive: version, OS, scripts and traceroute at once
-oN fileSave the readable output to a file

Saving your results

Save the output of any scan worth keeping. The -oN flag writes the readable report to a file, and -oA writes all three formats at once so you can grep the results or feed them into other tools later.

bash
nmap -sV -oN scan.txt example-host     # save readable output
nmap -sV -oA scan example-host         # save .nmap, .gnmap and .xml
Next step

Once a scan shows open ports, run -sV -sC against just those ports to learn versions and catch common misconfigurations before you go further.

Install

shell
sudo apt install nmap        # Debian, Ubuntu, Kali
sudo dnf install nmap        # Fedora, RHEL, Rocky
brew install nmap            # macOS
# Windows: run the signed installer from nmap.org/download.html

Example

shell
# scan the common ports with service and version detection
nmap -sV --top-ports 1000 scanme.nmap.org

# check specific ports on a host you control
nmap -p 22,80,443 192.168.1.10
Authorized use only

Run this against your own lab or systems you have written permission to test — nothing else.