CmdKeys LogoCommand Quiz

Nmap Command Practice

nmap (Network Mapper) discovers open ports, running services, and OS fingerprints on authorised hosts by sending carefully crafted probes. This track drills the flags that control what nmap scans, how fast it scans, how it identifies services, and how it writes results — the subset you reach for during a legitimate audit or lab exercise.

Command Reference

ports

CommandDescription
nmap -F <target>Scan the 100 most common ports on a target — faster than a full scan, covers the ports most likely to be open.
nmap -p <port> <target>Scan a single specific port on a target host.
nmap -p <start>-<end> <target>Scan a contiguous range of ports on a target — useful for auditing a known service port band.
nmap -r -p <start>-<end> <target>Scan a port range in consecutive order instead of the default randomised order — useful for predictable audit logs.
nmap -p- <target>Scan all 65535 ports on a target — comprehensive but slow; combine with a faster timing template on trusted networks.

detection

CommandDescription
nmap -sV <target>Probe open ports to determine the service name and version number running on each.
nmap --traceroute <target>Trace the network path (hops) from the scanner to the target host alongside the port scan.
nmap -O <target>Attempt to identify the operating system of the target based on TCP/IP stack fingerprinting (requires root).
nmap -sC <target>Run the default set of NSE scripts against open ports to gather additional service information.
nmap -A <target>Enable aggressive detection: service version (-sV), OS fingerprinting (-O), default scripts (-sC), and traceroute — all in one flag.
nmap --reason <target>Include the reason each port was classified as open, closed, or filtered — useful for understanding firewall behaviour.

timing

CommandDescription
nmap -T3 <target>Use the normal (default) timing template — balances speed and reliability on most networks.
nmap -T4 <target>Use the aggressive timing template — faster scans suited for reliable, low-latency networks such as CTF labs.
nmap -T0 <target>Use the paranoid timing template — extremely slow, one probe at a time, minimising detection by intrusion detection systems.
nmap --max-rate <rate> <target>Cap the scan to at most the given number of packets per second — prevents overwhelming a slow or sensitive target.
nmap --min-parallelism <numprobes> <target>Require nmap to keep at least the given number of probes in flight simultaneously — speeds up slow scans on reliable networks.

output

CommandDescription
nmap -oN <file> <target>Save scan results in human-readable normal format to a file for later review.
nmap -oX <file> <target>Save scan results in XML format — suitable for import into vulnerability management tools and parsers.
nmap -v <target>Enable verbose output — nmap reports open ports as it finds them rather than waiting until the scan completes.
nmap -oG <file> <target>Save scan results in grepable format — one host per line, easy to filter with grep and awk for scripted post-processing.
nmap -oA <basename> <target>Save scan results simultaneously in all major formats (normal, XML, grepable) using a shared file basename.

combined

CommandDescription
nmap -F -v <target>Scan the 100 most common ports with verbose output so results appear as each port is probed rather than at the end.
nmap -sV -p <port> <target>Probe a specific port to identify the exact service version — faster than scanning all ports when the port is already known.
nmap -sC -sV <target>Run default NSE scripts and detect service versions together — the standard combination for an authorised service enumeration.
nmap -sV -O -p- -T4 <target>Comprehensive authorised audit: scan all ports, detect service versions and OS, using the aggressive timing template.
nmap -A -T4 -oA <basename> <target>Aggressive scan (all detections) with aggressive timing, saving all three output formats under a shared basename.

discovery

CommandDescription
nmap -PR -sn <target>Discover live hosts on a local network using ARP requests — the most reliable method on a LAN without scanning ports.
nmap -PE -sn <target>Send ICMP echo (ping) requests to discover live hosts — checks reachability without scanning ports.
nmap -PS -sn <target>Send TCP SYN packets to discover live hosts — effective when ICMP is blocked by a firewall.
nmap -PU -sn <target>Send UDP packets to probe for live hosts — finds hosts with open UDP services that would not respond to ICMP or TCP pings.
nmap -PA -sn <target>Send TCP ACK packets to probe for live hosts — useful for identifying stateless firewall rules that block SYN but pass ACK.

Key Use Cases

  • Scan the 100 most common ports on a host with -F for a quick audit
  • Detect the service version and OS on open ports with -sV and -O
  • Control scan aggressiveness with timing templates (-T0 through -T5) to avoid overwhelming a target
  • Save scan results to all output formats at once with -oA for later analysis
  • Run default NSE scripts with -sC to enumerate additional service information
  • Trace the network path to a target alongside the port scan using --traceroute

Frequently Asked Questions

What is the difference between nmap -sV and nmap -A?

-sV probes open ports to determine the service version. -A is an aggressive shorthand that enables -sV (service detection), -O (OS detection), -sC (default scripts), and --traceroute all at once. Use -A when you want a comprehensive profile in a single command on an authorised target.

What does the -T timing template control?

-T sets the timing aggressiveness from -T0 (paranoid, very slow) through -T3 (normal default) to -T5 (insane — fastest but may drop packets). -T4 is commonly used for CTF labs and trusted networks; -T3 is the safe default for production.

What is the difference between -oN, -oX, and -oG output formats?

-oN writes human-readable normal output to a file. -oX writes structured XML suitable for import into other tools. -oG writes grep-able output with each host on one line, useful for shell post-processing. Use -oA to write all three simultaneously with a common basename.

Why does nmap require root or sudo for some scan types?

Certain scan techniques require the ability to craft raw network packets, which needs root privileges. Service detection (-sV) and connect scans work without root. OS detection (-O) typically requires root as well. Always scan only hosts you are authorised to test.

Ready to master Nmap commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →