Enumeration with Nmap
CPTS Notes
- Start Here
- General Framework
- Enumeration
- Enumeration with Nmap
- Reference
- Port References
- Linux Commands Cheatsheet
Set victim target (ease for repeating commands)
export TARGET=.Always scan all 65535 ports before concluding a port is closed.
Workflow
- Quick sweep: find open ports fast, start working immediately.
sudo nmap -sS --top-ports 1000 -T4 -oA scans/quick $TARGET- Full TCP: confirm you missed nothing (all 65535 ports).
sudo nmap -p- --min-rate 5000 -T4 -oA scans/allports $TARGET- Targeted deep scan:
-sC -sVonly on the ports found open.
sudo nmap -p 22,80,445 -sC -sV -oA scans/deep $TARGET- UDP: top ports, runs in the background while you work TCP.
sudo nmap -sU --top-ports 100 -T4 -oA scans/udp $TARGETReuse step-2 output to build the port list:
ports=$(grep open scans/allports.gnmap | grep -oP '\d+/open' | cut -d/ -f1 | paste -sd,)
Host discovery
Ping sweep
sudo nmap -sn 192.168.1.0/24If a host “looks down” but you know it’s there, always add
-Pn.
Skip ICMP ping
sudo nmap -Pn $TARGETTCP SYN ping to specific ports
sudo nmap -PS22,80,443 $TARGETScan types
| Flag | Scan | Notes |
|---|---|---|
-sS |
TCP SYN (stealth) | Default when root. Fast, half-open. |
-sT |
TCP connect | Non-root fallback. Full handshake, noisier. |
-sU |
UDP | Slow. Catches SNMP/DNS/TFTP/SMB. |
-sV |
Version detection | Probes banners to ID service versions. |
-sC |
Default scripts | --script=default. Safe recon NSE. |
-A |
Aggressive | -sC -sV -O --traceroute combined. |
-O |
OS detection | Needs root. Guesses from TCP/IP stack. |
Port states
Nmap reports one of six states per port.
| State | When you see it | Likely cause | What you deduce |
|---|---|---|---|
| open | Probe got a positive reply (SYN scan SYN/ACK, UDP a service response) |
An application is actively listening and accepting connections | Service is live. enumerate it. Your main attack surface. |
| closed | Probe reached the port and got a RST (TCP) or ICMP port-unreachable (UDP) |
Port is reachable but nothing is listening on it | Host is up and not firewalling this port. No service now, but confirms reachability. Could open later. |
| filtered | No reply at all, or an ICMP admin-prohibited/unreachable error | A firewall / IPS / router is dropping the probe before it reaches the port | Something is blocking you. Can’t tell if a service exists. Try -Pn, different source port, or another scan type. |
| open|filtered | No response, so Nmap can’t decide | Either an open service that simply doesn’t reply, or a firewall silently dropped the probe | Treat as maybe open, worth probing with -sV / manual connection. Very common in UDP and stealth scans (-sF/-sN/-sX). |
| closed|filtered | Only with Idle scan (-sI) |
Nmap can’t tell whether closed or filtered | Rare on HTB-like boxes. Ignore unless doing idle scans. |
| unfiltered | Only with ACK scan (-sA), port got a RST |
Port is reachable (no stateful firewall blocking) but open/closed is unknown | Firewall-mapping info only. Follow up with a SYN/connect scan to learn open vs closed. |
Key intuition, why “no reply” is ambiguous:
- TCP SYN scan:
SYN/ACK→ open,RST→ closed, silence → filtered. - UDP: a service reply → open, ICMP unreachable → closed, silence → open|filtered (most UDP services don’t answer empty probes).
filteredandopen|filteredwaste real time. If a known-useful port shows filtered, add-Pn, try-sT, or--source-port 53before assuming it’s dead.
Timing & performance
| Flag | Effect |
|---|---|
-T4 |
Aggressive timing. Good default for labs. |
--min-rate 5000 |
Push packets/sec. Big speedup on -p- scans. |
--max-retries 1 |
Don’t waste time retrying filtered ports. |
--open |
Only show open ports in output. |
-v |
Verbose. Reports open ports as they’re found. |
-T5is faster but drops accuracy on flaky targets. Stick to-T4.
NSE scripts
Run the vuln category:
sudo nmap --script vuln $TARGETRun safe and discovery categories:
sudo nmap --script safe,discovery $TARGETSMB enumeration:
sudo nmap -p445 --script smb-enum-shares,smb-os-discovery $TARGETHTTP enumeration:
sudo nmap -p80 --script http-enum,http-title $TARGETFTP anonymous login test:
sudo nmap -p21 --script ftp-anon $TARGETFind scripts by keyword:
sudo ls /usr/share/nmap/scripts | grep smbRead a script’s help:
sudo nmap --script-help http-enum
--script vulnis handy but noisy and not exhaustive. Never a substitute for manual service enumeration.
Output
| Flag | Format |
|---|---|
-oN file.nmap |
Normal (human-readable). |
-oG file.gnmap |
Greppable (extract ports easily). |
-oX file.xml |
XML (feed into other tools). |
-oA scans/base |
All three at once. Always use this. |
Save every scan under
scans/. You need this evidence for the report, and re-scanning wastes time.
UDP notes
UDP is slow because closed ports rarely reply. Don’t scan all 65535 UDP. Top 100-200 is enough. High-value UDP finds:
| Port | Service | Follow-up |
|---|---|---|
| 53 | DNS | zone transfer, subdomain enum |
| 69 | TFTP | anon file read/write |
| 161 | SNMP | snmpwalk community strings |
| 500 | IKE/VPN | ike-scan |
sudo nmap -sU -sV --top-ports 200 --open -T4 -oA scans/udp $TARGETFirewall / filtering basics
Target drops ICMP, treat as up
-PnConnect scan when SYN is filtered
-sTSpoof source port (some filters trust DNS)
--source-port 53Fragment packets (basic IDS evasion)
-fPad packets
--data-length 25On HTB-like boxes you rarely fight real firewalls. Start simple, add
-Pnif discovery fails, and don’t burn time on evasion unless a port is clearly filtered.