Network Scanning
Nmap
The definitive network mapper for host discovery, ports, and service/version detection.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Mapping live hosts and services on networks you are authorized to test.
How
Start with host discovery, then top ports, then full ports + scripts on interesting hosts.
Why
Foundation of almost every network assessment; NSE scripts extend enumeration.
Commands & usage
nmap -sn 192.168.1.0/24
nmap -sS -sV -sC -O -p- -T4 -oA full 192.168.1.10
nmap --script vuln 192.168.1.10
nmap -p 80,443 --script http-enum 192.168.1.10
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
ATT&CK
OWASP
Recipes
Tags
Related in Network Scanning
Masscan
Asynchronous ultra-fast port scanner for large address spaces.
RustScan
Fast port discovery that pipes open ports into Nmap automatically.
naabu
Fast port scanner from ProjectDiscovery, pipeline-friendly.
AutoRecon
Multi-threaded automatic enumeration of services based on open ports.
Netdiscover
ARP reconnaissance tool for local network host discovery.
arp-scan
Sends ARP requests to enumerate hosts on local subnets.