All cheatsheets

Cheatsheet · beginner

Nmap staged scan

Professional pacing: discover → top ports → full ports → scripts → version, with saves.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

nmap
scanning
enum

Host discovery

Command
nmap -sn 10.10.10.0/24 -oA scans/01-discovery
Command
nmap -sn -PR 10.10.10.0/24  # ARP on local L2

Fast service pass

Command
nmap -sS -sV -sC --top-ports 1000 -oA scans/02-top1000 TARGET
Command
nmap -sU --top-ports 50 -oA scans/02u-udp TARGET  # optional UDP

Full TCP (when time allows)

Command
nmap -sS -p- --min-rate 1000 -oA scans/03-alltcp TARGET
Command
nmap -sV -sC -p $(tr ',' '\n' < scans/03-alltcp.nmap | ... )  # re-version open ports
Command
nmap -sV -sC -p- -oA scans/04-full-sv TARGET  # slower all-in-one

Targeted scripts

Prefer specific scripts over blanket --script vuln on fragile prod.

Command
nmap -p 445 --script smb-enum-shares,smb-os-discovery TARGET
Command
nmap -p 80,443 --script http-title,http-headers,ssl-enum-ciphers TARGET
Command
nmap -p 88,389,636 --script ldap* TARGET  # lab AD only

Checklist

  • Outputs saved with -oA into dated folder
  • Scope file used (-iL) on multi-host jobs
  • Notes updated with interesting ports only
  • Aggressive scripts justified in RoE