One command tells you what services a machine exposes โ the first move of every engagement and the most-asked interview topic in the industry.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
Ships with Kali. On other distros: sudo apt install nmap.
Discovery only โ no ports touched. Only scan networks you own.
Your bread and butter: service versions + safe default scripts against Metasploitable2.
Default Nmap checks only 1,000 ports. The good stuff often hides above that.
-oA writes all formats. In jobs and OSCP, scans you didn't save never happened.
| -sS | Stealth SYN scan (default as root) |
| -sV | Probe service/version info |
| -sC | Default NSE scripts |
| -O | OS detection |
| -p- | All 65,535 ports |
| -A | Aggressive: -sV -sC -O + traceroute |
| --script=vuln | Run vuln-detection scripts |
| -Pn | Skip host discovery (treat as up) |
| -oA name | Save all output formats |
| -T4 | Faster timing (labs; avoid on prod) |
Chain it: rustscan for speed โ nmap -sV -sC on found ports.
The NSE library (script=vuln, http-enum, smb-os-discovery) is a whole second tool hiding inside.
In HTB/THM always start: nmap -sC -sV โ then -p- in background while you explore.
Learn --top-ports 100 for quick passes.
Use Nmap only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.