Nmap Scan Types, -D: performs a decoy scan.


 

Nmap Scan Types, A complete guide for security students and professionals. The analysts who become strong . Installing Nmap on Ubuntu To install Nmap on Ubuntu 22. Each one corresponds to a specific TCP/IP behavior, and understanding those behaviors is the difference between running scans and reading scan results intelligently. Typical usage scenarios and instructions are given for each scan type, as are on-the-wire packet traces illustrating how they work. Aug 19, 2019 · Use case six To perform a stealth scan for TCP information, use the -sT option. Jun 6, 2026 · Nmap (Network Mapper) is an open-source tool for network discovery and security auditing. Jul 6, 2026 · This article is part of the complete Nmap guide, and it walks the full family of TCP scan types, shows what each one detects, and (more usefully) shows where each one lies to you when the target stack does not play by the rules. From basic reconnaissance to advanced evasion techniques, this guide covers it all. 1. Nmap Switches and Scan Types – How to Use Nmap (Network Mapper) is the Swiss Army knife of network reconnaissance, offering a variety of scan types and switches that can help you discover services, detect vulnerabilities, and map network topologies. This comprehensive cheat sheet provides an extensive reference for Nmap (Network Mapper), the industry-standard tool for network discovery, security auditing, and vulnerability assessment. Sep 27, 2018 · My collection of nmap scan types, mostly used switches and their description. It is one of the most extensively used tools by network administrators and conversely attackers for reconnaissance (enumeration), the first step in the 5 phases of hacking. The --scanflags option allows you to design your own scan by specifying arbitrary TCP flags. -D: performs a decoy scan. Start with -sS -sV for most TCP work, add -sU –top-ports 100 -sV for UDP coverage, and reach for the more specialized scans when you have a specific reason. This chapter describes each of those scan types in depth. Aug 3, 2022 · It is essentially a port scanner that helps you scan networks and identify various ports and services available in the network, besides also providing further information on targets, including reverse DNS names, operating system guesses, device types, and MAC addresses. 0/24 RUN Security Considerations When using Nmap, always: Obtain proper authorization Nmap automatically generates a random number of decoys for the scan and randomly positions the real IP address between the decoy IP addresses. Jan 18, 2026 · Master network scanning with Nmap using real commands, scan types, NSE scripts, and evasion techniques. In addition to the interesting ports table, Nmap can provide further information on targets, including reverse DNS names, operating system guesses, device types, and MAC addresses. Jul 23, 2025 · Nmap is a security auditing tool used in the security field to actively enumerate a target system/network. Jul 23, 2025 · In this Nmap Cheat Sheet, you'll learn all the basics to advanced like basic scanning techniques, discovery options in Nmap, Firewall evasion techniques, version detection, output options, scripting engines and more. Custom Scan Types with --scanflags Truly advanced Nmap users need not limit themselves to the canned scanned types. 04, use the following command: sudo apt update sudo apt install nmap RUN Basic Nmap Command Structure nmap [scan type] [options] [target] RUN Simple Scanning Examples Scan a single IP address: nmap 192. 100 RUN Scan an entire subnet: nmap 192. This section documents the dozen or so port scan techniques supported by Nmap. We can use it to discover assets to attack or defend. This section covers only options that relate to port scans, and often describes only the port-scanning-related functionality of those options. It allows cybersecurity professionals to scan hosts and services, identify active systems, open ports and potential vulnerabilities, making it essential for network reconnaissance and risk assessment. Command-line Flags While the tutorial showed how simple executing an Nmap port scan can be, dozens of command-line flags are available to make the system more powerful and flexible. May 6, 2026 · Nmap scan types are not interchangeable. Such issues are specific to certain scan types and so are discussed in the individual scan type entries. Nmap - The Network Mapper Nmap has for a long time been considered as the standard port scanner for both network engineers and security professionals. Aug 9, 2023 · Learn about four common types of Nmap scans: TCP SYN, OS detection, vulnerability and version detection. This type of scan is handy when you can't use the -sS (SYN) type scan, which is the default—and is stealthier than the TCP connect scan shown below: Exploring further These six use cases will start you in the right direction with Nmap. Also, discover best practices for Nmap scanning. May 6, 2026 · The most common Nmap scan types are TCP SYN scan (-sS) for fast and quiet port discovery, TCP connect scan (-sT) for unprivileged users, UDP scan (-sU) for services like DNS and SNMP, and IP protocol scan (-sO) for non-TCP and non-UDP traffic. Nmap is used to actively probe the target network for active hosts (host discovery), port scanning, OS detection When an IP protocol scan is requested (-sO), Nmap provides information on supported IP protocols rather than listening ports. 168. ntfx, j3uk, qg8, rvbpgm2, b1blq, m6qe, qg9j, h6cmc, qczko, uyg,