Nmap Cheat Sheet

Target Specification

nmap a single IP
nmap specific IPs
nmap a range
nmap scanme.nmap.orgScan a domain
nmap using CIDR notation
-iLnmap -iL targets.txtScan targets from a file
-iRnmap -iR 100Scan 100 random hosts
–excludenmap –exclude listed hosts

Scan Techniques

-sSnmap -sSTCP SYN port scan (Default)
-sTnmap -sTTCP connect port scan (Default without root privilege)
-sUnmap -sUUDP port scan
-sAnmap -sATCP ACK port scan
-sWnmap -sWTCP Window port scan
-sMnmap -sMTCP Maimon port scan

Host Discovery

-sLnmap -sLNo Scan. List targets only
-snnmap -snDisable port scanning. Host discovery only.
-Pnnmap -PnDisable host discovery. Port scan only.
-PSnmap -PS22-25,80TCP SYN discovery on port x.
Port 80 by default
-PAnmap -PA22-25,80TCP ACK discovery on port x.
Port 80 by default
-PUnmap -PU53UDP discovery on port x.
Port 40125 by default
-PRnmap -PRARP discovery on local network
-nnmap -nNever do DNS resolution

Port Specification

-pnmap -p 21Port scan for port x
-pnmap -p 21-100Port range
-pnmap -p U:53,T:21-25,80Port scan multiple TCP and UDP ports
-pnmap -p-Port scan all ports
-pnmap -p http,httpsPort scan from service name
-Fnmap -FFast port scan (100 ports)
–top-portsnmap –top-ports 2000Port scan the top x ports
-p-65535nmap -p-65535Leaving off initial port in range makes the scan start at port 1
-p0-nmap -p0-Leaving off end port in range
makes the scan go through to port 65535

Service and Version Detection

-sVnmap -sVAttempts to determine the version of the service running on port
-sV –version-intensitynmap -sV –version-intensity 8Intensity level 0 to 9. Higher number increases possibility of correctness
-sV –version-lightnmap -sV –version-lightEnable light mode. Lower possibility of correctness. Faster
-sV –version-allnmap -sV –version-allEnable intensity level 9. Higher possibility of correctness. Slower
-Anmap -AEnables OS detection, version detection, script scanning, and traceroute

OS Detection

-Onmap -ORemote OS detection using TCP/IP stack fingerprinting
-O –osscan-limitnmap -O –osscan-limitIf at least one open and one closed TCP port are not found it will not try OS detection against host
-O –osscan-guessnmap -O –osscan-guessMakes Nmap guess more aggressively
-O –max-os-triesnmap -O –max-os-tries 1Set the maximum number x of OS detection tries against a target
-Anmap -AEnables OS detection, version detection, script scanning, and traceroute

Timing and Performance

-T0nmap -T0Paranoid (0) Intrusion Detection System evasion
-T1nmap -T1Sneaky (1) Intrusion Detection System evasion
-T2nmap -T2Polite (2) slows down the scan to use less bandwidth and use less target machine resources
-T3nmap -T3Normal (3) which is default speed
-T4nmap -T4Aggressive (4) speeds scans; assumes you are on a reasonably fast and reliable network
-T5nmap -T5Insane (5) speeds scan; assumes you are on an extraordinarily fast network

Timing and Performance Switches

–host-timeout <time>1s; 4m; 2hGive up on target after this long
–min-rtt-timeout/max-rtt-timeout/initial-rtt-timeout <time>1s; 4m; 2hSpecifies probe round trip time
–min-hostgroup/max-hostgroup <size<size>50; 1024Parallel host scan group sizes
–min-parallelism/max-parallelism <numprobes>10; 1Probe parallelization
–max-retries <tries>3Specify the maximum number of port scan probe retransmissions
–min-rate <number>100Send packets no slower than <number> per second
–max-rate <number>100Send packets no faster than <number> per second

NSE Scripts

-sCnmap -sCScan with default NSE scripts. Considered useful for discovery and safe
–script defaultnmap –script defaultScan with default NSE scripts. Considered useful for discovery and safe
–scriptnmap –script=bannerScan with a single script. Example banner
–scriptnmap –script=http*Scan with a wildcard. Example http
–scriptnmap –script=http,bannerScan with two scripts. Example http and banner
–scriptnmap –script “not intrusive”Scan default, but remove intrusive scripts
–script-argsnmap –script snmp-sysdescr –script-args snmpcommunity=admin script with arguments

Useful NSE Script Examples

nmap -Pn –script=http-sitemap-generator scanme.nmap.orghttp site map generator
nmap -n -Pn -p 80 –open -sV -vvv –script banner,http-title -iR 1000Fast search for random web servers
nmap -Pn –script=dns-brute domain.comBrute forces DNS hostnames guessing subdomains
nmap -n -Pn -vv -O -sV –script smb-enum*,smb-ls,smb-mbenum,smb-os-discovery,smb-s*,smb-vuln*,smbv2* -vv SMB scripts to run
nmap –script whois* domain.comWhois query
nmap -p80 –script http-unsafe-output-escaping scanme.nmap.orgDetect cross site scripting vulnerabilities
nmap -p80 –script http-sql-injection scanme.nmap.orgCheck for SQL injections

Firewall / IDS Evasion and Spoofing

-fnmap -fRequested scan (including ping scans) use tiny fragmented IP packets. Harder for packet filters
–mtunmap –mtu 32Set your own offset size
-Dnmap -D,,, scans from spoofed IPs
-Dnmap -D decoy-ip1,decoy-ip2,your-own-ip,decoy-ip3,decoy-ip4 remote-host-ipAbove example explained
-Snmap -S www.microsoft.com www.facebook.comScan Facebook from Microsoft (-e eth0 -Pn may be required)
-gnmap -g 53 given source port number
–proxiesnmap –proxies, connections through HTTP/SOCKS4 proxies
–data-lengthnmap –data-length 200 random data to sent packets

Example IDS Evasion command

nmap -f -t 0 -n -Pn –data-length 200 -D,,,


-oNnmap -oN normal.fileNormal output to the file normal.file
-oXnmap -oX xml.fileXML output to the file xml.file
-oGnmap -oG grep.fileGrepable output to the file grep.file
-oAnmap -oA resultsOutput in the three major formats at once
-oG –nmap -oG –Grepable output to screen. -oN -, -oX – also usable
–append-outputnmap -oN file.file –append-outputAppend a scan to a previous scan file
-vnmap -vIncrease the verbosity level (use -vv or more for greater effect)
-dnmap -dIncrease debugging level (use -dd or more for greater effect)
–reasonnmap –reasonDisplay the reason a port is in a particular state, same output as -vv
–opennmap –openOnly show open (or possibly open) ports
–packet-tracenmap -T4 –packet-traceShow all packets sent and received
–iflistnmap –iflistShows the host interfaces and routes
–resumenmap –resume results.fileResume a scan

Helpful Nmap Output examples

nmap -p80 -sV -oG – –open | grep openScan for web servers and grep to show which IPs are running web servers
nmap -iR 10 -n -oX out.xml | grep “Nmap” | cut -d ” ” -f5 > live-hosts.txtGenerate a list of the IPs of live hosts
nmap -iR 10 -n -oX out2.xml | grep “Nmap” | cut -d ” ” -f5 >> live-hosts.txtAppend IP to the list of live hosts
ndiff scanl.xml scan2.xmlCompare output from nmap using the ndif
xsltproc nmap.xml -o nmap.htmlConvert nmap xml files to html files
grep ” open ” results.nmap | sed -r ‘s/ +/ /g’ | sort | uniq -c | sort -rn | lessReverse sorted list of how often ports turn up

Miscellaneous Options

-6nmap -6 2607:f0d0:1002:51::4Enable IPv6 scanning
-hnmap -hnmap help screen

Other Useful Nmap Commands

nmap -iR 10 -PS22-25,80,113,1050,35000 -v -snDiscovery only on ports x, no port scan
nmap -PR -sn -vvArp discovery only on local network, no port scan
nmap -iR 10 -sn -tracerouteTraceroute to random targets, no port scan
nmap -sL –dns-server the Internal DNS for hosts, list targets only
    Thanks a lot for the information. it is very useful.

    That will be a helpful tipsheet. Thank you so much. I can learn more about it. looking forward to the hacking course from you.

    Looking forward to it. I use nmap most days but only use a limited number of switches.

    Keep the good hands-on stuff coming

    Thank you very much in deed, very useful, I will buy your course on nmap, I want to insist about a Firewall course there aren't around, I guess it is a good investment for you, I bought already all your courses and they are the best! Please keep going!

    Great news.
    In expectation of this course.
    As usual ,
    Thanks for what you doing.

    I think this is very Useful,Thank you soo much.Am enjoying the training and practice.

    Love it. Thank you Nathan!

    Muchas gracias ,,, me fue de utilidad,,,

    How to test .net Web services using ZenMap

    Thank you for sharing this information!

    Thank you for this cheatsheet.
    I think there is a mistake concerning the -sS switch. It is not the default one.
    Normally, -sT is the default one and -sS needs root privileges.

    This is very helpful. Thanks a lot!

    Sir this is very helpfull and very important for firewall point of view,
    But what about port knock if a system or server is using port knock to active its any port for a client. Any method by nmap that can bypass port knock.

    Thank you

    • Nathan House says:

      The basic port knocking method uses a fixed sequence of ports. This method is not protected cryptographically so there are the following attacks possible:

      brute-force — If you use the full range of possible ports 1—65535 then even very short knocking sequences give impressive number of combinations to test. For example for 3 knocks with randomly generated sequence it is 65535³ ≈ 2.8×10¹⁴. Another aspect to consider is that the port which will open after the knocking could be unknown so the attacker would have to repeatedly scan the ports during the port knocking attempts. — The number of combinations to try can be lowered if some information about the ports being used is known (for example a subset of ports) or if there is a successful random number generator attack.
      Measure against such attacks except securing the mentioned possible vulnerabilities could be disabling of the access from the attacker source IP address after certain number of unsuccessful attempts during certain time period. Unfortunately this makes the system vulnerable to DoS attacks by attacker locking your access by using your IP address as a spoofed source address.
      sniffing — The port knocking sequence is not protected cryptographically so an attacker can sniff the successful port knocking sequence. The port knocking sequence could also leak from logs of the destination system itself of from a network monitoring system.
      Measure against this attack is use of one-time knocking sequences (analogy of one-time passwords). The one-time sequence could be a hash computed from a secret and some of the following: source IP address, time, event counter etc.
      man in the middle — Captured one-time knocking sequences cannot be reused but a port-knocking access can be exploited by a man-in-the-middle attack. The attacker in the path of your communication (possibly redirected) can relay your successful communication, see and modify anything.
      The port-knocking itself is performed by one-way communication as such it cannot be protected against MITM. Also the communication following the port knocking must be secured against MITM to retain the security. To ensure this we can use standard encrypted protocols like SSL or SSH.

    Great stuff!

    Can you please help me understand the main difference between
    nmap -O and nmap -A

    • Nathan House says:

      nmap -O = Remote OS detection using TCP/IP stack fingerprinting

      nmap -A = Enables OS detection PLUS – version detection, script scanning, and traceroute

      So -O is only OS detection, -A is OS detection PLUS – version detection, script scanning, and traceroute

    Thanks Man , That’s Help me a lot .
    i wanna ask , what is the main different between -sn AND -Pn ;
    what is the network discovery do exactly and port scan !!

    hi sir ,
    i just wanna know , is there any benefit for this -sL option ? and when do i use -P0 ?

    • Nathan House says:

      -sL does no scan and just lists targets only to be scanned.
      The list scan is a degenerate form of host discovery that simply lists each host of the network(s) specified, without sending any packets to the target hosts. By default, Nmap still does reverse-DNS resolution on the hosts to learn their names. It is often surprising how much useful information simple hostnames give out. For example, fw.chi is the name of one company’s Chicago firewall. Nmap also reports the total number of IP addresses at the end. The list scan is a good sanity check to ensure that you have proper IP addresses for your targets. If the hosts sport domain names you do not recognize, it is worth investigating further to prevent scanning the wrong company’s network. Since the idea is to simply print a list of target hosts, options for higher level functionality such as port scanning, OS detection, or ping scanning cannot be combined with this. If you wish to disable ping scanning while still performing such higher level functionality, read up on the -Pn (skip ping) option.

      -PO (IP Protocol Ping)
      One of the newer host discovery options is the IP protocol ping, which sends IP packets with the specified protocol number set in their IP header. The protocol list takes the same format as do port lists in the previously discussed TCP, UDP and SCTP host discovery options. If no protocols are specified, the default is to send multiple IP packets for ICMP (protocol 1), IGMP (protocol 2), and IP-in-IP (protocol 4). The default protocols can be configured at compile-time by changingDEFAULT_PROTO_PROBE_PORT_SPEC in nmap.h. Note that for the ICMP, IGMP, TCP (protocol 6), UDP (protocol 17) and SCTP (protocol 132), the packets are sent with the proper protocol headers while other protocols are sent with no additional data beyond the IP header (unless any of –data, –data-string, or –data-length options are specified). This host discovery method looks for either responses using the same protocol as a probe, or ICMP protocol unreachable messages which signify that the given protocol isn’t supported on the destination host. Either type of response signifies that the target host is alive.

        Yea i read this , but i dont get it , in short words give me what is -P0 used for ??

        • Nathan House says:

          Do you know what IP protocols are? like 1 ICMP Internet Control Message Protocol RFC 792, 2 IGMP Internet Group Management Protocol RFC 1112.

          It sends IP packets with the specified protocol number set in the IP header. It’s an alternative discovery method.

    Great! I was just wondering "gosh, if there could be a pdf version and – woah, there is"

    sirr i need your help
    i thing u help mee

    Very good article

    Thank you Nathan.

    Very great article I tried to build, an online command simulator

    This is so awesome! I'm taking your course now and my only regret is I didn't do this sooner! This could've saved me soooo much headache and time! But it's ok! Best way to learn is through error lol. Now that I know all the things NOT to do, you are showing the way. Thank you Mr. House.

  • Network Napper says:

    Great article and quite good presentation
    I built and online version of nmap here so such commands
    like described here i like them.

    man u may live long , may God bless u ok

    Appreciate it Arthur.

    When was the last time you updated your course Nathan?

    • Nathan House says:

      nmap doesn't change quickly in terms of how you use the tool. The last major release Nmap 7.00 was November 9, 2015. We are still on 7 now. The course was created well after this.

    Sir, plez show bobs en vagene.. thank kindly sir I owe you, you r best god bless sir

    Wow – this is awesome. I was in the throes of creating my own, and well, yours looks much better than mine. Much appreciated!

    thank you sir nathan!

    Thank you very much Sir, for this NMAP Cheat sheet, I am from India, and enrolled in your the Complete Cyber Security Volume 1,2,3,4, loved your content and way of explaining #StaySafeOnline

    What does nmap do other than scan for vunerailitites?

    • Nathan House says:

      It's not really a vulnerability scanner, although it can do that with a script. It is for discovering hosts and open ports.

    thank you for the detailed nmap cheat sheet.

    Awesome stuff, I am getting ready to graduate from MHCC with a Cybersecurity/Networking degree, realizing I still have a lot to learn.

    Hi! I am trying to find on my network IP addresses that have MySQL open using Nmap. Is any help available? Thanks in advance

    • Nathan House says:

      Scan from outside your network and look for the MySQL ports. Port 3306 is the default port for the classic MySQL protocol ( port ), which is used by the mysql client, MySQL Connectors, and utilities such as mysqldump and mysqlpump.

    Hi Nathan, maybe add movie name Sneakers and replace David with Marty. Like Marty's friend said "too many secrets". Cheers

    So it means we don't need to get the course of Nmap on Udemy from you, all of it is here ?

    BEST sir….
    Love from INDIA

    Hey Nathan,

    I appreciate the cheat sheet with really good explanations of each Nmap parameter. So I’ve included this article as a reference in my CSS Pen testing report, Thanks again!

    nice blog bro

    Thank you so much!!!

    Yes! It’s true.. YOU are THE NMAP KING!
    I’ve learned things here that my mother wouldn’t even teach me. Thanks so much.
    USA (Now a Trump free zone! 🙂

    I think the nmap full course and scanning techniques there are the best available. Never mind the midland accent its great but the explanations are best best.

Systematics and cogent.

    Systematics and cogent.

    Thank you for this course! And the brilliant accent!
All the best, Steven
    All the best, Steven

    nmap test answers please

    Very Usefull.

    This is awesome! Thanks

    My God, this is so cool & Important

    Grate job. Thanks a lot

    Ola! Apesar que sou bem cru no assunto, Coisas impotante pego para aprender um pouco.
Valeu abraço.
    Valeu abraço.

    this man is genius in nmap and cyber security like mike meyers
i have to see his courses .
    i have to see his courses .

    Thanks for this..!!

    Thanks Nathan. What a great resource!

    Great courses Thanks again Nathan

    Nice I want to learn

    THANK YOU!!! I used to use Legion but for some reason the frontend is proving unreliable, so I need to put on my big boy pants and use Nmap the proper way.

    Thank you! It's content like this that helps make the membership cost worth it. Don't get me wrong, the sheer content on the website makes it worth the cost but this stuff is just icing on the cake!

  • >