Skip to content
Pentesting and ethical hacking

Nmap commands cheat sheet: 25 commands with real output

Nmap commands cheat sheet: 25 commands for discovery, port scans, version and OS detection, NSE scripts and output, each with real lab output.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 11 min read

These are the 25 Nmap commands you will use most, grouped in the order you would use them on a real engagement: find hosts, find ports, identify services, run scripts, save results. Every example was run against our own lab network or against scanme.nmap.org, and each shows the output you should expect, so you know what “working” looks like.

Legal note: only scan systems you own or have written permission to test. Port scanning someone else’s network without permission can breach computer misuse laws and your internet provider’s terms. The Nmap project explains the issues in its legal guide.

The lab used for these examples

All private-range scans target a VirtualBox host-only network, 192.168.56.0/24, built as described in our home lab guide (the Windows Server segment and the static IPs are additions beyond the basic home-lab guide):

IP Machine Role
192.168.56.10 Ubuntu Server 24.04 Web server for a fictional company, Acme Fintech
192.168.56.20 Windows 11 Staff workstation
10.10.20.20 Windows Server 2022 File server on a second, routed lab segment; firewall blocks ping
192.168.56.30 Debian 12 FTP and SSH box
192.168.56.5 Kali Linux The scanner

The one public target is scanme.nmap.org, which the Nmap project explicitly allows for light test scans. Do not hammer it.

Most commands use sudo: as root, Nmap can send raw packets for SYN scans, OS detection and ARP discovery. Your timings and versions will differ; the shape of the output will not.

Host discovery: what is alive?

1. Ping sweep a subnet: -sn

$ sudo nmap -sn 192.168.56.0/24
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:02 WAT
Nmap scan report for 192.168.56.1
Host is up (0.00019s latency).
MAC Address: 0A:00:27:00:00:00 (Unknown)
Nmap scan report for 192.168.56.10
Host is up (0.00052s latency).
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.20
Host is up (0.00061s latency).
MAC Address: 08:00:27:B4:91:07 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.30
Host is up (0.00048s latency).
MAC Address: 08:00:27:6E:02:D9 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.5
Host is up.
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.04 seconds

-sn means “no port scan”. On a local subnet with root, Nmap uses ARP requests, which is why hosts that ignore ping still show as up on the same subnet.

2. List targets without scanning: -sL

$ nmap -sL 192.168.56.8/30
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:03 WAT
Nmap scan report for 192.168.56.8
Nmap scan report for 192.168.56.9
Nmap scan report for 192.168.56.10
Nmap scan report for 192.168.56.11
Nmap done: 4 IP addresses (0 hosts up) scanned in 0.01 seconds

No packets reach the targets. Use it to check a scope range expands as you expect.

3. Exclude hosts: --exclude

$ sudo nmap -sn 192.168.56.0/24 --exclude 192.168.56.1,192.168.56.5
...
Nmap done: 254 IP addresses (3 hosts up) scanned in 1.98 seconds

Essential when the scope says “everything except the production database”.

4. Read targets from a file: -iL

$ cat targets.txt
192.168.56.10
192.168.56.30
$ sudo nmap -iL targets.txt -F
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:05 WAT
Nmap scan report for 192.168.56.10
Host is up (0.00044s latency).
Not shown: 96 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
443/tcp  open  https
3306/tcp open  mysql
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)

Nmap scan report for 192.168.56.30
...
Nmap done: 2 IP addresses (2 hosts up) scanned in 0.31 seconds

Fewer typos, easier to audit.

5. Skip host discovery: -Pn

Without it, a host that drops ping and has no ARP path (for example, across a router) looks dead:

$ nmap 10.10.20.20
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.04 seconds

$ nmap -Pn 10.10.20.20
Nmap scan report for 10.10.20.20
Host is up (0.0011s latency).
Not shown: 995 filtered tcp ports (no-response)
PORT     STATE SERVICE
135/tcp  open  msrpc
139/tcp  open  netbios-ssn
445/tcp  open  microsoft-ds
3389/tcp open  ms-wbt-server
5985/tcp open  wsman
Nmap done: 1 IP address (1 host up) scanned in 4.87 seconds

-Pn treats every target as up, so large ranges scan slower.

Port scanning: which doors are open?

6. Default scan

$ sudo nmap 192.168.56.10
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:08 WAT
Nmap scan report for 192.168.56.10
Host is up (0.00041s latency).
Not shown: 996 closed tcp ports (reset)
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open  http
443/tcp  open  https
3306/tcp open  mysql
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)

Nmap done: 1 IP address (1 host up) scanned in 0.29 seconds

By default Nmap scans the 1,000 most common TCP ports. The SERVICE column is a guess from the port number, not a check of what is listening (see the Nmap reference guide for every option).

7. Specific ports: -p

$ sudo nmap -p 22,80,443,8080 192.168.56.10
PORT     STATE  SERVICE
22/tcp   open   ssh
80/tcp   open   http
443/tcp  open   https
8080/tcp closed http-proxy

Ranges work too: -p 1-1024, and you can mix protocols with -p U:53,T:22,80.

8. All 65,535 ports: -p-

$ sudo nmap -p- 192.168.56.10
Not shown: 65530 closed tcp ports (reset)
PORT      STATE SERVICE
22/tcp    open  ssh
80/tcp    open  http
443/tcp   open  https
3306/tcp  open  mysql
50051/tcp open  unknown
Nmap done: 1 IP address (1 host up) scanned in 3.12 seconds

The default scan missed port 50051. Developers love high ports for internal APIs, which is exactly why a full scan belongs in every test.

9. Fast scan: -F

-F scans the top 100 ports instead of 1,000: a quick first look at a big range (output as in command 4).

10. Top N ports: --top-ports

$ sudo nmap --top-ports 20 192.168.56.30
PORT     STATE  SERVICE
21/tcp   open   ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
53/tcp   closed domain
80/tcp   closed http
...
3389/tcp closed ms-wbt-server

Unlike the default output, --top-ports with a small number lists closed ports too, because there are too few to summarise.

11. Show only open ports: --open

$ sudo nmap --top-ports 20 --open 192.168.56.30
PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh

Cleaner output, especially across a subnet.

12. TCP SYN scan: -sS

$ sudo nmap -sS -p 22,80 192.168.56.10
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http

The default as root. Nmap sends a SYN, reads the reply (SYN/ACK open, RST closed) and never completes the handshake. Quieter in application logs, but intrusion detection still sees it.

13. TCP connect scan: -sT

$ nmap -sT -p 22,80 192.168.56.10
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
Nmap done: 1 IP address (1 host up) scanned in 0.06 seconds

The default without root. Nmap asks the operating system to make full connections, so the target’s services may log them. The port scanning techniques chapter explains each scan type.

14. UDP scan: -sU

$ sudo nmap -sU --top-ports 20 192.168.56.30
PORT      STATE         SERVICE
53/udp    closed        domain
67/udp    closed        dhcps
68/udp    open|filtered dhcpc
69/udp    closed        tftp
123/udp   closed        ntp
161/udp   open          snmp
...
Nmap done: 1 IP address (1 host up) scanned in 21.37 seconds

UDP is slow (no handshake), and open|filtered means no reply, so Nmap cannot tell which. Don’t skip it: SNMP on 161 with a default community string is a classic finding.

15. Show why Nmap decided: --reason

$ sudo nmap --reason -p 22,25,3306 192.168.56.10
PORT     STATE  SERVICE REASON
22/tcp   open   ssh     syn-ack ttl 64
25/tcp   closed smtp    reset ttl 64
3306/tcp open   mysql   syn-ack ttl 64

A TTL of 64 usually points to Linux; Windows typically starts at 128.

Service and OS detection: what is running?

16. Service versions: -sV

$ sudo nmap -sV -p 22,80,443,3306,50051 192.168.56.10
PORT      STATE SERVICE  VERSION
22/tcp    open  ssh      OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
80/tcp    open  http     Apache httpd 2.4.58 ((Ubuntu))
443/tcp   open  ssl/http Apache httpd 2.4.58 ((Ubuntu))
3306/tcp  open  mysql    MySQL 8.0.39-0ubuntu0.24.04.2
50051/tcp open  unknown
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
...
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

This turns “port 80 is open” into “Apache 2.4.58 is running”, which you can then check against vendor advisories. When Nmap cannot match a service, as with port 50051 here, connect to it manually and look. Treat versions as evidence to verify, not proof: distributions backport fixes without changing the version number.

17. OS detection: -O

$ sudo nmap -O 192.168.56.10
...
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19
Network Distance: 1 hop

It needs one open and one closed port to be reliable, and it is a fingerprint match: read it as “probably”.

18. Aggressive scan: -A

$ sudo nmap -A -p 21,22 192.168.56.30
PORT   STATE SERVICE VERSION
21/tcp open  ftp     vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r--    1 0        0            1043 Oct 02 09:14 staff-list.csv
22/tcp open  ssh     OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
| ssh-hostkey:
|   256 9c:41:2e:7a:58:0d:b3:6f:e1:20:4c:9a:11:7e:c2:58 (ECDSA)
|_  256 0e:d8:73:15:a4:6b:92:c0:3e:5f:88:21:d7:46:af:13 (ED25519)
...
OS details: Linux 4.15 - 5.19
TRACEROUTE
HOP RTT     ADDRESS
1   0.49 ms 192.168.56.30

-A combines -sV, -O, default scripts and traceroute. Here it found anonymous FTP exposing a staff list in one command. It is noisy, so save it for narrowed-down targets.

Nmap Scripting Engine (NSE)

NSE scripts extend Nmap from port scanner to lightweight vulnerability checker. Browse them all in the NSE documentation.

19. Default scripts: -sC

-sC runs Nmap’s default script category (mostly safe, but not guaranteed non-intrusive).

$ sudo nmap -sC -p 80,443 192.168.56.10
PORT    STATE SERVICE
80/tcp  open  http
|_http-title: Acme Fintech Staff Portal
443/tcp open  https
| ssl-cert: Subject: commonName=portal.acme-fintech.test
| Not valid before: 2026-01-12T00:00:00
|_Not valid after:  2027-01-12T23:59:59
|_http-title: Acme Fintech Staff Portal

The certificate’s common name just leaked an internal hostname.

20. Named scripts: --script

$ sudo nmap -p 80 --script http-headers,http-methods 192.168.56.10
PORT   STATE SERVICE
80/tcp open  http
| http-headers:
|   Date: Sat, 10 Oct 2026 09:14:02 GMT
|   Server: Apache/2.4.58 (Ubuntu)
|   Content-Type: text/html; charset=UTF-8
|   Connection: close
|
|_  (Request type: HEAD)
| http-methods:
|_  Supported Methods: GET POST OPTIONS HEAD

No security headers and a full server banner: small findings, still reportable.

21. SMB checks on Windows

$ sudo nmap -p 445 --script smb-protocols,smb2-security-mode -Pn 10.10.20.20
PORT    STATE SERVICE
445/tcp open  microsoft-ds

Host script results:
| smb-protocols:
|   dialects:
|     2:0:2
|     2:1:0
|     3:0:0
|     3:0:2
|_    3:1:1
| smb2-security-mode:
|   3:1:1:
|_    Message signing enabled but not required

SMBv1 is absent (good), but signing is not required, which allows relay attacks: a common internal pentest finding.

22. TLS configuration: ssl-enum-ciphers

$ sudo nmap -p 443 --script ssl-enum-ciphers 192.168.56.10
PORT    STATE SERVICE
443/tcp open  https
| ssl-enum-ciphers:
|   TLSv1.2:
|     ciphers:
|       TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
|       TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
|     ...
|   TLSv1.3:
|     ciphers:
|       TLS_AKE_WITH_AES_128_GCM_SHA256 (ecdh_x25519) - A
|       TLS_AKE_WITH_AES_256_GCM_SHA384 (ecdh_x25519) - A
|     ...
|_  least strength: A

A clean result. If you see TLSv1.0 or ciphers graded C or worse, that is a finding.

Speed and output

23. Timing templates: -T

$ sudo nmap -T4 -F 192.168.56.0/24
...
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.61 seconds

-T0 (paranoid) to -T5 (insane). -T4 suits a lab. On client networks, agree speed in the rules of engagement; aggressive timing can knock over fragile devices.

24. Save every format: -oA

$ sudo nmap -sV -oA acme-web 192.168.56.10
$ ls acme-web.*
acme-web.gnmap  acme-web.nmap  acme-web.xml
$ grep open acme-web.gnmap
Host: 192.168.56.10 ()	Ports: 22/open/tcp//ssh//OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)/, 80/open/tcp//http//Apache httpd 2.4.58 ((Ubuntu))/, ...

Always save output: .nmap for humans, .xml for other tools, and the grepable format for shell one-liners.

25. A light scan of the public test host

$ nmap -sV -p 22,80,9929,31337 scanme.nmap.org
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:41 WAT
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.19s latency).
Other addresses for scanme.nmap.org (not scanned): 2600:3c01::f03c:91ff:fe18:bb2f

PORT      STATE SERVICE    VERSION
22/tcp    open  ssh        OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp    open  http       Apache httpd 2.4.7 ((Ubuntu))
9929/tcp  open  nping-echo Nping echo
31337/tcp open  tcpwrapped
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Nmap done: 1 IP address (1 host up) scanned in 7.92 seconds

The one internet host you may practise on without asking. Keep scans light, and expect results to change as the Nmap project maintains it.

A sensible order for a real scan

Put the commands together like this on an authorised internal test:

  1. sudo nmap -sn -iL scope.txt -oA 01-discovery to find live hosts.
  2. sudo nmap -p- --open -iL live.txt -oA 02-allports to find every open TCP port.
  3. sudo nmap -sV -sC -p <ports> -iL live.txt -oA 03-services on what you found.
  4. sudo nmap -sU --top-ports 50 -iL live.txt -oA 04-udp for the UDP basics.
  5. Targeted --script runs on interesting services.

That sequence mirrors the discovery phase in NIST SP 800-115, the classic technical guide to security testing. Nmap only finds doors; deciding which ones matter is the tester’s job. For the full picture of where scanning fits, see how to become a penetration tester and our beginner’s penetration testing toolkit.

FAQ

Is Nmap legal? The tool is legal. Using it against systems you do not own or have permission to test may not be. Get written permission first, every time.

Why does my scan show different results without sudo? Without root privileges Nmap cannot craft raw packets, so it uses connect scans, cannot do ARP discovery, and refuses to run OS detection (-O) without root.

What does “filtered” mean? Nmap got no reply, or an ICMP “administratively prohibited” message, usually because a firewall dropped the probe. It cannot tell whether a service is behind it.