All cheatsheets
Cheatsheet · beginner
Nmap staged scan
Professional pacing: discover → top ports → full ports → scripts → version, with saves.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
nmap
scanning
enum
Host discovery
Command
nmap -sn 10.10.10.0/24 -oA scans/01-discovery
Command
nmap -sn -PR 10.10.10.0/24 # ARP on local L2
Fast service pass
Command
nmap -sS -sV -sC --top-ports 1000 -oA scans/02-top1000 TARGET
Command
nmap -sU --top-ports 50 -oA scans/02u-udp TARGET # optional UDP
Full TCP (when time allows)
Command
nmap -sS -p- --min-rate 1000 -oA scans/03-alltcp TARGET
Command
nmap -sV -sC -p $(tr ',' '\n' < scans/03-alltcp.nmap | ... ) # re-version open ports
Command
nmap -sV -sC -p- -oA scans/04-full-sv TARGET # slower all-in-one
Targeted scripts
Prefer specific scripts over blanket --script vuln on fragile prod.
Command
nmap -p 445 --script smb-enum-shares,smb-os-discovery TARGET
Command
nmap -p 80,443 --script http-title,http-headers,ssl-enum-ciphers TARGET
Command
nmap -p 88,389,636 --script ldap* TARGET # lab AD only
Checklist
- Outputs saved with -oA into dated folder
- Scope file used (-iL) on multi-host jobs
- Notes updated with interesting ports only
- Aggressive scripts justified in RoE