home/toolvault/recon & scanning/nmap

Nmap //

Recon & Scanningscanner

One command tells you what services a machine exposes โ€” the first move of every engagement and the most-asked interview topic in the industry.

difficulty ยท easy
5 min
time to first win
5
guided steps
0
students started here*

HOW TO USE NMAP

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

nmap โ€” guided lab session
static view
step 01

Verify the install

nmap --version

Ships with Kali. On other distros: sudo apt install nmap.

step 02

Ping-sweep your LAB network

nmap -sn 10.0.2.0/24

Discovery only โ€” no ports touched. Only scan networks you own.

step 03

Default script + version scan

nmap -sV -sC 10.0.2.4

Your bread and butter: service versions + safe default scripts against Metasploitable2.

step 04

All ports, fast

nmap -p- -T4 --min-rate 1000 10.0.2.4

Default Nmap checks only 1,000 ports. The good stuff often hides above that.

step 05

Save evidence

nmap -sV -sC -oA scan1 10.0.2.4

-oA writes all formats. In jobs and OSCP, scans you didn't save never happened.

THE WORKFLOW AT A GLANCE

๐ŸŽฏ
Target
lab IP or range
๐Ÿ“ก
Discover
-sn who's alive
๐Ÿšช
Ports
what's open?
๐Ÿ”Ž
Versions
-sV -sC detail
๐Ÿ—‚๏ธ
Report
-oA evidence
LEARNING CURVE
easy โ€” 5 min to first win

FLAGS & SUPER-MOVES

-sSStealth SYN scan (default as root)
-sVProbe service/version info
-sCDefault NSE scripts
-OOS detection
-p-All 65,535 ports
-AAggressive: -sV -sC -O + traceroute
--script=vulnRun vuln-detection scripts
-PnSkip host discovery (treat as up)
-oA nameSave all output formats
-T4Faster timing (labs; avoid on prod)

PRO TIPS

01

Chain it

Chain it: rustscan for speed โ†’ nmap -sV -sC on found ports.

02

The NSE library (script=vuln, http-enum, smb-os-discovery) is a whole second tool hiding inside.

The NSE library (script=vuln, http-enum, smb-os-discovery) is a whole second tool hiding inside.

03

In HTB/THM always start

In HTB/THM always start: nmap -sC -sV โ†’ then -p- in background while you explore.

04

Learn --top-ports 100 for quick passes.

Learn --top-ports 100 for quick passes.

โš–๏ธ

Golden rule

Use Nmap only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.