~/enumeration-with-nmap

Enumeration with Nmap

CPTS Notes6 min read

Set victim target (ease for repeating commands)

export TARGET=.

Always scan all 65535 ports before concluding a port is closed.

Workflow

  1. Quick sweep: find open ports fast, start working immediately.
sudo nmap -sS --top-ports 1000 -T4 -oA scans/quick $TARGET
  1. Full TCP: confirm you missed nothing (all 65535 ports).
sudo nmap -p- --min-rate 5000 -T4 -oA scans/allports $TARGET
  1. Targeted deep scan: -sC -sV only on the ports found open.
sudo nmap -p 22,80,445 -sC -sV -oA scans/deep $TARGET
  1. UDP: top ports, runs in the background while you work TCP.
sudo nmap -sU --top-ports 100 -T4 -oA scans/udp $TARGET

Reuse step-2 output to build the port list: ports=$(grep open scans/allports.gnmap | grep -oP '\d+/open' | cut -d/ -f1 | paste -sd,)

Host discovery

Ping sweep

sudo nmap -sn 192.168.1.0/24

If a host “looks down” but you know it’s there, always add -Pn.

Skip ICMP ping

sudo nmap -Pn $TARGET

TCP SYN ping to specific ports

sudo nmap -PS22,80,443 $TARGET

Scan types

Flag Scan Notes
-sS TCP SYN (stealth) Default when root. Fast, half-open.
-sT TCP connect Non-root fallback. Full handshake, noisier.
-sU UDP Slow. Catches SNMP/DNS/TFTP/SMB.
-sV Version detection Probes banners to ID service versions.
-sC Default scripts --script=default. Safe recon NSE.
-A Aggressive -sC -sV -O --traceroute combined.
-O OS detection Needs root. Guesses from TCP/IP stack.

Port states

Nmap reports one of six states per port.

State When you see it Likely cause What you deduce
open Probe got a positive reply (SYN scan SYN/ACK, UDP a service response) An application is actively listening and accepting connections Service is live. enumerate it. Your main attack surface.
closed Probe reached the port and got a RST (TCP) or ICMP port-unreachable (UDP) Port is reachable but nothing is listening on it Host is up and not firewalling this port. No service now, but confirms reachability. Could open later.
filtered No reply at all, or an ICMP admin-prohibited/unreachable error A firewall / IPS / router is dropping the probe before it reaches the port Something is blocking you. Can’t tell if a service exists. Try -Pn, different source port, or another scan type.
open|filtered No response, so Nmap can’t decide Either an open service that simply doesn’t reply, or a firewall silently dropped the probe Treat as maybe open, worth probing with -sV / manual connection. Very common in UDP and stealth scans (-sF/-sN/-sX).
closed|filtered Only with Idle scan (-sI) Nmap can’t tell whether closed or filtered Rare on HTB-like boxes. Ignore unless doing idle scans.
unfiltered Only with ACK scan (-sA), port got a RST Port is reachable (no stateful firewall blocking) but open/closed is unknown Firewall-mapping info only. Follow up with a SYN/connect scan to learn open vs closed.

Key intuition, why “no reply” is ambiguous:

  • TCP SYN scan: SYN/ACK → open, RST → closed, silence → filtered.
  • UDP: a service reply → open, ICMP unreachable → closed, silence → open|filtered (most UDP services don’t answer empty probes).

filtered and open|filtered waste real time. If a known-useful port shows filtered, add -Pn, try -sT, or --source-port 53 before assuming it’s dead.

Timing & performance

Flag Effect
-T4 Aggressive timing. Good default for labs.
--min-rate 5000 Push packets/sec. Big speedup on -p- scans.
--max-retries 1 Don’t waste time retrying filtered ports.
--open Only show open ports in output.
-v Verbose. Reports open ports as they’re found.

-T5 is faster but drops accuracy on flaky targets. Stick to -T4.

NSE scripts

Run the vuln category:

sudo nmap --script vuln $TARGET

Run safe and discovery categories:

sudo nmap --script safe,discovery $TARGET

SMB enumeration:

sudo nmap -p445 --script smb-enum-shares,smb-os-discovery $TARGET

HTTP enumeration:

sudo nmap -p80 --script http-enum,http-title $TARGET

FTP anonymous login test:

sudo nmap -p21 --script ftp-anon $TARGET

Find scripts by keyword:

sudo ls /usr/share/nmap/scripts | grep smb

Read a script’s help:

sudo nmap --script-help http-enum

--script vuln is handy but noisy and not exhaustive. Never a substitute for manual service enumeration.

Output

Flag Format
-oN file.nmap Normal (human-readable).
-oG file.gnmap Greppable (extract ports easily).
-oX file.xml XML (feed into other tools).
-oA scans/base All three at once. Always use this.

Save every scan under scans/. You need this evidence for the report, and re-scanning wastes time.

UDP notes

UDP is slow because closed ports rarely reply. Don’t scan all 65535 UDP. Top 100-200 is enough. High-value UDP finds:

Port Service Follow-up
53 DNS zone transfer, subdomain enum
69 TFTP anon file read/write
161 SNMP snmpwalk community strings
500 IKE/VPN ike-scan
sudo nmap -sU -sV --top-ports 200 --open -T4 -oA scans/udp $TARGET

Firewall / filtering basics

Target drops ICMP, treat as up

-Pn

Connect scan when SYN is filtered

-sT

Spoof source port (some filters trust DNS)

--source-port 53

Fragment packets (basic IDS evasion)

-f

Pad packets

--data-length 25

On HTB-like boxes you rarely fight real firewalls. Start simple, add -Pn if discovery fails, and don’t burn time on evasion unless a port is clearly filtered.