nmap
Port, service and version scanner for mapping what a host exposes.
Nmap is a port scanner that maps what a host exposes on the network: which ports are open, what service is listening on each, and often the exact version. It is usually the first tool you run against a target, because a clear list of open ports tells you where to look next. This page takes you from a clean install to the handful of commands you will use on almost every scan.
Use it only on systems you own or are authorized to test.
Installing Nmap
Nmap ships in every major package manager, so installation is a single command on most systems. On Windows the signed installer also sets up the Npcap driver that Nmap needs to send raw packets.
sudo apt install nmap # Debian, Ubuntu, Kali sudo dnf install nmap # Fedora, RHEL, Rocky brew install nmap # macOS
# Windows: download and run the installer from nmap.org/download.html nmap --version # confirm the install on any platform
Your first scan
The simplest useful scan names a target and lets Nmap check the most common ports. Run it against scanme.nmap.org, a host the Nmap project keeps online for exactly this kind of practice.
$ nmap scanme.nmap.org PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 9929/tcp open nping-echo
Each line is a port. STATE open means something is listening and accepting connections, closed means the port answered but nothing is there, and filtered means a firewall dropped the probe so Nmap could not tell. The SERVICE column is Nmap best guess from the port number, which the next step confirms.
Naming ports and targets
By default Nmap checks the 1000 most common ports. The -p flag changes that to a list, a range, or every port, and you can aim at one host or a whole subnet in the same command.
nmap -p 80,443 example-host # just these two ports nmap -p 1-1000 example-host # a range of ports nmap -p- example-host # all 65535 ports nmap 192.168.1.0/24 # every host in a subnet
Service and version detection
Knowing a port is open is only the start; the next question is what is running on it. The -sV flag reads banners to identify the service and version, -sC adds a set of safe scripts, and -A turns on everything at once for a lab.
nmap -sV example-host # identify service versions nmap -sV -sC example-host # add the default NSE scripts nmap -A example-host # version, OS, scripts and traceroute
| Flag | What it does |
|---|---|
-sV | Detect the service and version on each open port |
-sC | Run the default set of safe NSE scripts |
-p | Choose ports: a list, a range, or -p- for all |
-Pn | Skip the ping check and scan a host that blocks ping |
-A | Aggressive: version, OS, scripts and traceroute at once |
-oN file | Save the readable output to a file |
Saving your results
Save the output of any scan worth keeping. The -oN flag writes the readable report to a file, and -oA writes all three formats at once so you can grep the results or feed them into other tools later.
nmap -sV -oN scan.txt example-host # save readable output nmap -sV -oA scan example-host # save .nmap, .gnmap and .xml
Once a scan shows open ports, run -sV -sC against just those ports to learn versions and catch common misconfigurations before you go further.
Install
sudo apt install nmap # Debian, Ubuntu, Kali sudo dnf install nmap # Fedora, RHEL, Rocky brew install nmap # macOS # Windows: run the signed installer from nmap.org/download.html
Example
# scan the common ports with service and version detection nmap -sV --top-ports 1000 scanme.nmap.org # check specific ports on a host you control nmap -p 22,80,443 192.168.1.10
Run this against your own lab or systems you have written permission to test — nothing else.