- Joined
- Dec 30, 2024
- Messages
- 388
- Reaction score
- 206
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 1,068
- USD
- 1,068
An Nmap cheat sheet is the fastest reference a penetration tester keeps open: Nmap (Network Mapper) is the standard network discovery and security auditing tool, and its flags fall into four groups - host discovery, port scanning, service/version detection, and output - so a one-screen reference covering the 40 commands you actually type beats scrolling man pages mid-engagement. This cheat sheet is organized by task: discovery first, then scan types, then the real-world recipes (target list, whole subnet, slow/noisy scans, firewall evasion), with every command runnable as-is on Kali Linux.
TL;DR - Pin the five commands you will use daily: nmap -sn for host discovery, nmap -sV -sC -p- for the full service scan, nmap -sS for the stealth TCP scan, nmap -O for OS detection, and nmap -oN result.nmap to save everything. Ports default to the top 1000 - always pass -p- when you mean all 65535. Host discovery before port scanning saves hours on big subnets, and --min-rate=500 keeps scans fast without looking like a flood.
HOST DISCOVERY - IS IT ALIVE?
Ping sweep the subnet, no port scan:
ARP scan inside your own LAN (most reliable at L2):
Skip host discovery, treat every host as up (for ping-blocked targets):
Single host, default checks:
SCAN TYPES - PICK YOUR NOISE LEVEL
SYN (-sS) is the daily driver: half-open handshake, no full connection, quiet logs on target. UDP scans are 5-10x slower than TCP - cap them with --top-ports or a tight -p list.
PORT SELECTION AND SPEED
Timing templates cover the same ground:
Use -T4 for lab and VPN engagements, -T2/-T3 on production you are told to be gentle with, never -T5 when accuracy matters.
SERVICE, VERSION, OS, SCRIPTS
The signature reconnaissance command - version detection, default scripts, all ports:
Version intensity control (0-9, higher = more probes):
OS detection and traceroute:
NSE scripts by category (default is safe only):
The full recon one-liner every engagement starts with:
-oA writes .nmap, .xml, and .gnmap of that name in one shot - the XML feeds Nessus and Metasploit later.
FIREWALL AND IDS EVASION
Decoy scanning (-D) works best when a real host is in the mix - pure RND decoys with your real IP absent looks as suspicious as the scan itself.
REAL-WORLD RECIPES
Whole subnet, services, saved:
Targets from a file (one host/CIDR per line):
Web server pass (what is behind this nginx):
Slow and quiet against a monitored target:
UDP services that matter (53, 161, 123, 69, 500):
OUTPUT FORMATS
Grepable format answers the mid-engagement question in one line - open 22/80/443 hosts across a sweep:
PRACTICAL FINGERPRINTS - WHAT THE OUTPUT TELLS YOU
COMMON MISTAKES
- Running -p- on a /16 "because thorough" - discovery first, scope the ports second
- Forgetting -Pn on filtered hosts and waiting for timeouts to expire
- Reading -sV output without --version-intensity on high ports (defaults to quiet probes)
- No -oA save, terminal scrolls away, work repeated
- -T5 on a target whose IDS bans the VPN IP mid-scan
FAQ
Q: Which Nmap scan should I run first?
A: nmap -sn for the alive hosts, then nmap -sV -sC -p- -T4 -oA pass1 against each one. That pair covers 90% of engagement reconnaissance.
Q: Why does Nmap show only 1000 ports by default?
A: The default target list is the top 1000 most common TCP ports. Use -p- when you need all 65535, and --top-ports with -sU for UDP.
Q: Is Nmap legal to use?
A: On networks you own or hold written authorization to assess, yes - it is the standard tool shipped for network auditing. Scanning without authorization is the actual offense, not the tool.
Q: How do I make Nmap output feed other tools?
A: Save with -oA or -oX, then import the XML into Nessus/ Metasploit, or grep the .gnmap files for a host list (grep "Open" hosts.gnmap).
RELATED ON BLACKHAT PAKISTAN
SQLMap Tutorial for Beginners 2026 - once Nmap maps the ports, sqlmap attacks the services.
Advanced Web Hacking Tools - the web-tier toolkit behind every port 80/443 hit.
Simple Dork Generator - the OSINT-side companion to active scanning.
WiFi Password Hack 2026 - Complete Guide - wireless scanning runs beside the wired sweep.
TL;DR - Pin the five commands you will use daily: nmap -sn for host discovery, nmap -sV -sC -p- for the full service scan, nmap -sS for the stealth TCP scan, nmap -O for OS detection, and nmap -oN result.nmap to save everything. Ports default to the top 1000 - always pass -p- when you mean all 65535. Host discovery before port scanning saves hours on big subnets, and --min-rate=500 keeps scans fast without looking like a flood.
HOST DISCOVERY - IS IT ALIVE?
Ping sweep the subnet, no port scan:
Code:
nmap -sn 192.168.1.0/24
ARP scan inside your own LAN (most reliable at L2):
Code:
nmap -sn -PR 192.168.1.0/24
Skip host discovery, treat every host as up (for ping-blocked targets):
Code:
nmap -Pn 10.10.10.5
Single host, default checks:
Code:
nmap 10.10.10.5
SCAN TYPES - PICK YOUR NOISE LEVEL
Code:
nmap -sS 10.10.10.5 TCP SYN (stealth, default as root)
nmap -sT 10.10.10.5 full TCP connect (no raw sockets, works unprivileged)
nmap -sU 10.10.10.5 UDP scan (slow - pair with top ports)
nmap -sU --top-ports 20 10.10.10.5 UDP top 20 (DNS, SNMP, NTP...)
nmap -sA 10.10.10.5 ACK scan - is the port filtered?
nmap -sN 10.10.10.5 NULL scan - no flags set
nmap -sF 10.10.10.5 FIN scan
nmap -sX 10.10.10.5 Xmas scan - FIN+PSH+URG
nmap -b ftp.target.com FTP bounce scan through a third-party relay
SYN (-sS) is the daily driver: half-open handshake, no full connection, quiet logs on target. UDP scans are 5-10x slower than TCP - cap them with --top-ports or a tight -p list.
PORT SELECTION AND SPEED
Code:
nmap -p 22,80,443 10.10.10.5 named ports
nmap -p 1-1000 10.10.10.5 range
nmap -p- 10.10.10.5 all 65535 ports (slow, thorough)
nmap --top-ports 100 10.10.10.5 most common 100
nmap -F 10.10.10.5 fast top 100
nmap --open 10.10.10.5 only open ports in output
nmap --min-rate=1000 --max-retries=1 10.10.10.5 speed cap for time-boxed scans
Timing templates cover the same ground:
Code:
nmap -T0 10.10.10.5 paranoid - IDS evasion, hours long
nmap -T1 10.10.10.5 sneaky
nmap -T2 10.10.10.5 polite - slower, lighter on target
nmap -T3 10.10.10.5 normal (default)
nmap -T4 10.10.10.5 aggressive - the pentest default
nmap -T5 10.10.10.5 insane - floods, may drop results
Use -T4 for lab and VPN engagements, -T2/-T3 on production you are told to be gentle with, never -T5 when accuracy matters.
SERVICE, VERSION, OS, SCRIPTS
The signature reconnaissance command - version detection, default scripts, all ports:
Code:
nmap -sV -sC -p- 10.10.10.5
Version intensity control (0-9, higher = more probes):
Code:
nmap -sV --version-intensity 7 -p 1-1000 10.10.10.5
OS detection and traceroute:
Code:
nmap -O --osscan-guess 10.10.10.5
nmap --traceroute 10.10.10.5
NSE scripts by category (default is safe only):
Code:
nmap --script=default 10.10.10.5
nmap --script=vuln 10.10.10.5
nmap --script=auth,safe 10.10.10.5
nmap --script=http-enum,http-headers,http-title 10.10.10.5
The full recon one-liner every engagement starts with:
Code:
nmap -sV -sC -O --traceroute -p- -T4 -oA recon/10.10.10.5 10.10.10.5
-oA writes .nmap, .xml, and .gnmap of that name in one shot - the XML feeds Nessus and Metasploit later.
FIREWALL AND IDS EVASION
Code:
nmap -f 10.10.10.5 fragment packets across MTU
nmap --mtu 24 10.10.10.5 custom fragment size (multiple of 8)
nmap -D RND:10 10.10.10.5 decoy scan - 10 random decoys mixed in
nmap -S 20.20.20.20 -e eth0 10.10.10.5 spoofed source IP
nmap --source-port=53 10.10.10.5 trusted source port
nmap --data-length=250 10.10.10.5 pad payload to randomize signatures
nmap --badsum 10.10.10.5 bogus checksum - response = something is filtering
Decoy scanning (-D) works best when a real host is in the mix - pure RND decoys with your real IP absent looks as suspicious as the scan itself.
REAL-WORLD RECIPES
Whole subnet, services, saved:
Code:
nmap -sn 192.168.1.0/24 -oG hosts.gnmap
nmap -iL hosts.gnmap.txt -sV -sC -T4 -oA lan_full
Targets from a file (one host/CIDR per line):
Code:
nmap -iL targets.txt -sV -T4 --open -oN open_hosts.nmap
Web server pass (what is behind this nginx):
Code:
nmap -p 80,443,8080,8443 -sV --script=http-title,http-headers 10.10.10.5
Slow and quiet against a monitored target:
Code:
nmap -sS -T2 --max-retries=2 --host-timeout 15m 10.10.10.5
UDP services that matter (53, 161, 123, 69, 500):
Code:
nmap -sU -p 53,161,123,69,500,1900 --version-intensity 4 10.10.10.5
OUTPUT FORMATS
Code:
nmap -oN result.nmap 10.10.10.5 human readable
nmap -oX result.xml 10.10.10.5 XML for tools
nmap -oG result.gnmap 10.10.10.5 grepable
nmap -oA basename 10.10.10.5 all three at once
nmap --resume session.nmap continue an interrupted scan
Grepable format answers the mid-engagement question in one line - open 22/80/443 hosts across a sweep:
Code:
grep "Open" hosts.gnmap | awk '{print $2}' | sort -u
PRACTICAL FINGERPRINTS - WHAT THE OUTPUT TELLS YOU
Code:
PORT STATE MEANING
22 open ssh - creds testing, key enum
80/443 open web - dir bust, tech stack, CVEs
139/445 open smb - enum4linux, eternalblue-era checks
3306 open mysql - hands off unless in scope
3389 open rdp - NLA status, bluekeep-era checks
445+139 open legacy shares - anonymous enum first
111 open rpcbind - mount enumeration
161/udp open snmp - community strings
53/udp open dns - zone transfer attempt (dig axfr)
COMMON MISTAKES
- Running -p- on a /16 "because thorough" - discovery first, scope the ports second
- Forgetting -Pn on filtered hosts and waiting for timeouts to expire
- Reading -sV output without --version-intensity on high ports (defaults to quiet probes)
- No -oA save, terminal scrolls away, work repeated
- -T5 on a target whose IDS bans the VPN IP mid-scan
FAQ
Q: Which Nmap scan should I run first?
A: nmap -sn for the alive hosts, then nmap -sV -sC -p- -T4 -oA pass1 against each one. That pair covers 90% of engagement reconnaissance.
Q: Why does Nmap show only 1000 ports by default?
A: The default target list is the top 1000 most common TCP ports. Use -p- when you need all 65535, and --top-ports with -sU for UDP.
Q: Is Nmap legal to use?
A: On networks you own or hold written authorization to assess, yes - it is the standard tool shipped for network auditing. Scanning without authorization is the actual offense, not the tool.
Q: How do I make Nmap output feed other tools?
A: Save with -oA or -oX, then import the XML into Nessus/ Metasploit, or grep the .gnmap files for a host list (grep "Open" hosts.gnmap).
RELATED ON BLACKHAT PAKISTAN
SQLMap Tutorial for Beginners 2026 - once Nmap maps the ports, sqlmap attacks the services.
Advanced Web Hacking Tools - the web-tier toolkit behind every port 80/443 hit.
Simple Dork Generator - the OSINT-side companion to active scanning.
WiFi Password Hack 2026 - Complete Guide - wireless scanning runs beside the wired sweep.
Code:
nmap -sn 192.168.1.0/24 live hosts
nmap -sV -sC -p- -T4 -oA recon IP full recon pass
nmap -sS -T4 --open IP stealthy open ports
nmap -O --osscan-guess IP OS fingerprint
nmap -sU --top-ports 20 IP quick UDP pass
nmap -D RND:10 -f IP decoy + fragment evasion
nmap -iL list.txt -oA out batch from file
nmap --resume saved.nmap continue scan
grep "Open" x.gnmap | awk '{print $2}' extract live+open hosts