• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

Nmap Cheat Sheet 2026 - 40+ Scan Commands and Flags Reference

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
388
Reaction score
206
Points
62
Website
blackhatpakistan.net
Points
1,068
USD
1,068
An Nmap cheat sheet is the fastest reference a penetration tester keeps open: Nmap (Network Mapper) is the standard network discovery and security auditing tool, and its flags fall into four groups - host discovery, port scanning, service/version detection, and output - so a one-screen reference covering the 40 commands you actually type beats scrolling man pages mid-engagement. This cheat sheet is organized by task: discovery first, then scan types, then the real-world recipes (target list, whole subnet, slow/noisy scans, firewall evasion), with every command runnable as-is on Kali Linux.

TL;DR - Pin the five commands you will use daily: nmap -sn for host discovery, nmap -sV -sC -p- for the full service scan, nmap -sS for the stealth TCP scan, nmap -O for OS detection, and nmap -oN result.nmap to save everything. Ports default to the top 1000 - always pass -p- when you mean all 65535. Host discovery before port scanning saves hours on big subnets, and --min-rate=500 keeps scans fast without looking like a flood.

HOST DISCOVERY - IS IT ALIVE?

Ping sweep the subnet, no port scan:

Code:
nmap -sn 192.168.1.0/24

ARP scan inside your own LAN (most reliable at L2):

Code:
nmap -sn -PR 192.168.1.0/24

Skip host discovery, treat every host as up (for ping-blocked targets):

Code:
nmap -Pn 10.10.10.5

Single host, default checks:

Code:
nmap 10.10.10.5

SCAN TYPES - PICK YOUR NOISE LEVEL

Code:
nmap -sS 10.10.10.5        TCP SYN (stealth, default as root)
nmap -sT 10.10.10.5        full TCP connect (no raw sockets, works unprivileged)
nmap -sU 10.10.10.5        UDP scan (slow - pair with top ports)
nmap -sU --top-ports 20 10.10.10.5   UDP top 20 (DNS, SNMP, NTP...)
nmap -sA 10.10.10.5        ACK scan - is the port filtered?
nmap -sN 10.10.10.5        NULL scan - no flags set
nmap -sF 10.10.10.5        FIN scan
nmap -sX 10.10.10.5        Xmas scan - FIN+PSH+URG
nmap -b ftp.target.com     FTP bounce scan through a third-party relay

SYN (-sS) is the daily driver: half-open handshake, no full connection, quiet logs on target. UDP scans are 5-10x slower than TCP - cap them with --top-ports or a tight -p list.

PORT SELECTION AND SPEED

Code:
nmap -p 22,80,443 10.10.10.5       named ports
nmap -p 1-1000 10.10.10.5            range
nmap -p- 10.10.10.5                  all 65535 ports (slow, thorough)
nmap --top-ports 100 10.10.10.5      most common 100
nmap -F 10.10.10.5                   fast top 100
nmap --open 10.10.10.5               only open ports in output
nmap --min-rate=1000 --max-retries=1 10.10.10.5   speed cap for time-boxed scans

Timing templates cover the same ground:

Code:
nmap -T0 10.10.10.5   paranoid - IDS evasion, hours long
nmap -T1 10.10.10.5   sneaky
nmap -T2 10.10.10.5   polite - slower, lighter on target
nmap -T3 10.10.10.5   normal (default)
nmap -T4 10.10.10.5   aggressive - the pentest default
nmap -T5 10.10.10.5   insane - floods, may drop results

Use -T4 for lab and VPN engagements, -T2/-T3 on production you are told to be gentle with, never -T5 when accuracy matters.

SERVICE, VERSION, OS, SCRIPTS

The signature reconnaissance command - version detection, default scripts, all ports:

Code:
nmap -sV -sC -p- 10.10.10.5

Version intensity control (0-9, higher = more probes):

Code:
nmap -sV --version-intensity 7 -p 1-1000 10.10.10.5

OS detection and traceroute:

Code:
nmap -O --osscan-guess 10.10.10.5
nmap --traceroute 10.10.10.5

NSE scripts by category (default is safe only):

Code:
nmap --script=default 10.10.10.5
nmap --script=vuln 10.10.10.5
nmap --script=auth,safe 10.10.10.5
nmap --script=http-enum,http-headers,http-title 10.10.10.5

The full recon one-liner every engagement starts with:

Code:
nmap -sV -sC -O --traceroute -p- -T4 -oA recon/10.10.10.5 10.10.10.5

-oA writes .nmap, .xml, and .gnmap of that name in one shot - the XML feeds Nessus and Metasploit later.

FIREWALL AND IDS EVASION

Code:
nmap -f 10.10.10.5                      fragment packets across MTU
nmap --mtu 24 10.10.10.5                   custom fragment size (multiple of 8)
nmap -D RND:10 10.10.10.5                  decoy scan - 10 random decoys mixed in
nmap -S 20.20.20.20 -e eth0 10.10.10.5     spoofed source IP
nmap --source-port=53 10.10.10.5           trusted source port
nmap --data-length=250 10.10.10.5          pad payload to randomize signatures
nmap --badsum 10.10.10.5                   bogus checksum - response = something is filtering

Decoy scanning (-D) works best when a real host is in the mix - pure RND decoys with your real IP absent looks as suspicious as the scan itself.

REAL-WORLD RECIPES

Whole subnet, services, saved:

Code:
nmap -sn 192.168.1.0/24 -oG hosts.gnmap
nmap -iL hosts.gnmap.txt -sV -sC -T4 -oA lan_full

Targets from a file (one host/CIDR per line):

Code:
nmap -iL targets.txt -sV -T4 --open -oN open_hosts.nmap

Web server pass (what is behind this nginx):

Code:
nmap -p 80,443,8080,8443 -sV --script=http-title,http-headers 10.10.10.5

Slow and quiet against a monitored target:

Code:
nmap -sS -T2 --max-retries=2 --host-timeout 15m 10.10.10.5

UDP services that matter (53, 161, 123, 69, 500):

Code:
nmap -sU -p 53,161,123,69,500,1900 --version-intensity 4 10.10.10.5

OUTPUT FORMATS

Code:
nmap -oN result.nmap 10.10.10.5       human readable
nmap -oX result.xml 10.10.10.5           XML for tools
nmap -oG result.gnmap 10.10.10.5         grepable
nmap -oA basename 10.10.10.5             all three at once
nmap --resume session.nmap                continue an interrupted scan

Grepable format answers the mid-engagement question in one line - open 22/80/443 hosts across a sweep:

Code:
grep "Open" hosts.gnmap | awk '{print $2}' | sort -u

PRACTICAL FINGERPRINTS - WHAT THE OUTPUT TELLS YOU

Code:
PORT     STATE  MEANING
22       open   ssh - creds testing, key enum
80/443   open   web - dir bust, tech stack, CVEs
139/445  open   smb - enum4linux, eternalblue-era checks
3306     open   mysql - hands off unless in scope
3389     open   rdp - NLA status, bluekeep-era checks
445+139  open   legacy shares - anonymous enum first
111      open   rpcbind - mount enumeration
161/udp  open   snmp - community strings
53/udp   open   dns - zone transfer attempt (dig axfr)

COMMON MISTAKES

- Running -p- on a /16 "because thorough" - discovery first, scope the ports second
- Forgetting -Pn on filtered hosts and waiting for timeouts to expire
- Reading -sV output without --version-intensity on high ports (defaults to quiet probes)
- No -oA save, terminal scrolls away, work repeated
- -T5 on a target whose IDS bans the VPN IP mid-scan

FAQ

Q: Which Nmap scan should I run first?
A: nmap -sn for the alive hosts, then nmap -sV -sC -p- -T4 -oA pass1 against each one. That pair covers 90% of engagement reconnaissance.

Q: Why does Nmap show only 1000 ports by default?
A: The default target list is the top 1000 most common TCP ports. Use -p- when you need all 65535, and --top-ports with -sU for UDP.

Q: Is Nmap legal to use?
A: On networks you own or hold written authorization to assess, yes - it is the standard tool shipped for network auditing. Scanning without authorization is the actual offense, not the tool.

Q: How do I make Nmap output feed other tools?
A: Save with -oA or -oX, then import the XML into Nessus/ Metasploit, or grep the .gnmap files for a host list (grep "Open" hosts.gnmap).

RELATED ON BLACKHAT PAKISTAN

SQLMap Tutorial for Beginners 2026 - once Nmap maps the ports, sqlmap attacks the services.
Advanced Web Hacking Tools - the web-tier toolkit behind every port 80/443 hit.
Simple Dork Generator - the OSINT-side companion to active scanning.
WiFi Password Hack 2026 - Complete Guide - wireless scanning runs beside the wired sweep.

Code:
nmap -sn 192.168.1.0/24                 live hosts
nmap -sV -sC -p- -T4 -oA recon IP         full recon pass
nmap -sS -T4 --open IP                    stealthy open ports
nmap -O --osscan-guess IP                 OS fingerprint
nmap -sU --top-ports 20 IP                quick UDP pass
nmap -D RND:10 -f IP                      decoy + fragment evasion
nmap -iL list.txt -oA out                 batch from file
nmap --resume saved.nmap                  continue scan
grep "Open" x.gnmap | awk '{print $2}'    extract live+open hosts
 
Threads
1,073Threads
Messages
2,132Messages
Members
3,704Members
Latest member
AlaricalaraLatest member
Top