These are the 25 Nmap commands you will use most, grouped in the order you would use them on a real engagement: find hosts, find ports, identify services, run scripts, save results. Every example was run against our own lab network or against scanme.nmap.org, and each shows the output you should expect, so you know what “working” looks like.
Legal note: only scan systems you own or have written permission to test. Port scanning someone else’s network without permission can breach computer misuse laws and your internet provider’s terms. The Nmap project explains the issues in its legal guide.
The lab used for these examples
All private-range scans target a VirtualBox host-only network, 192.168.56.0/24, built as described in our home lab guide (the Windows Server segment and the static IPs are additions beyond the basic home-lab guide):
| IP | Machine | Role |
|---|---|---|
| 192.168.56.10 | Ubuntu Server 24.04 | Web server for a fictional company, Acme Fintech |
| 192.168.56.20 | Windows 11 | Staff workstation |
| 10.10.20.20 | Windows Server 2022 | File server on a second, routed lab segment; firewall blocks ping |
| 192.168.56.30 | Debian 12 | FTP and SSH box |
| 192.168.56.5 | Kali Linux | The scanner |
The one public target is scanme.nmap.org, which the Nmap project explicitly allows for light test scans. Do not hammer it.
Most commands use sudo: as root, Nmap can send raw packets for SYN scans, OS detection and ARP discovery. Your timings and versions will differ; the shape of the output will not.
Host discovery: what is alive?
1. Ping sweep a subnet: -sn
$ sudo nmap -sn 192.168.56.0/24
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:02 WAT
Nmap scan report for 192.168.56.1
Host is up (0.00019s latency).
MAC Address: 0A:00:27:00:00:00 (Unknown)
Nmap scan report for 192.168.56.10
Host is up (0.00052s latency).
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.20
Host is up (0.00061s latency).
MAC Address: 08:00:27:B4:91:07 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.30
Host is up (0.00048s latency).
MAC Address: 08:00:27:6E:02:D9 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.5
Host is up.
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.04 seconds
-sn means “no port scan”. On a local subnet with root, Nmap uses ARP requests, which is why hosts that ignore ping still show as up on the same subnet.
2. List targets without scanning: -sL
$ nmap -sL 192.168.56.8/30
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:03 WAT
Nmap scan report for 192.168.56.8
Nmap scan report for 192.168.56.9
Nmap scan report for 192.168.56.10
Nmap scan report for 192.168.56.11
Nmap done: 4 IP addresses (0 hosts up) scanned in 0.01 seconds
No packets reach the targets. Use it to check a scope range expands as you expect.
3. Exclude hosts: --exclude
$ sudo nmap -sn 192.168.56.0/24 --exclude 192.168.56.1,192.168.56.5
...
Nmap done: 254 IP addresses (3 hosts up) scanned in 1.98 seconds
Essential when the scope says “everything except the production database”.
4. Read targets from a file: -iL
$ cat targets.txt
192.168.56.10
192.168.56.30
$ sudo nmap -iL targets.txt -F
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:05 WAT
Nmap scan report for 192.168.56.10
Host is up (0.00044s latency).
Not shown: 96 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
3306/tcp open mysql
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.30
...
Nmap done: 2 IP addresses (2 hosts up) scanned in 0.31 seconds
Fewer typos, easier to audit.
5. Skip host discovery: -Pn
Without it, a host that drops ping and has no ARP path (for example, across a router) looks dead:
$ nmap 10.10.20.20
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.04 seconds
$ nmap -Pn 10.10.20.20
Nmap scan report for 10.10.20.20
Host is up (0.0011s latency).
Not shown: 995 filtered tcp ports (no-response)
PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3389/tcp open ms-wbt-server
5985/tcp open wsman
Nmap done: 1 IP address (1 host up) scanned in 4.87 seconds
-Pn treats every target as up, so large ranges scan slower.
Port scanning: which doors are open?
6. Default scan
$ sudo nmap 192.168.56.10
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:08 WAT
Nmap scan report for 192.168.56.10
Host is up (0.00041s latency).
Not shown: 996 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
3306/tcp open mysql
MAC Address: 08:00:27:3A:5C:1E (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 0.29 seconds
By default Nmap scans the 1,000 most common TCP ports. The SERVICE column is a guess from the port number, not a check of what is listening (see the Nmap reference guide for every option).
7. Specific ports: -p
$ sudo nmap -p 22,80,443,8080 192.168.56.10
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
8080/tcp closed http-proxy
Ranges work too: -p 1-1024, and you can mix protocols with -p U:53,T:22,80.
8. All 65,535 ports: -p-
$ sudo nmap -p- 192.168.56.10
Not shown: 65530 closed tcp ports (reset)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
3306/tcp open mysql
50051/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 3.12 seconds
The default scan missed port 50051. Developers love high ports for internal APIs, which is exactly why a full scan belongs in every test.
9. Fast scan: -F
-F scans the top 100 ports instead of 1,000: a quick first look at a big range (output as in command 4).
10. Top N ports: --top-ports
$ sudo nmap --top-ports 20 192.168.56.30
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp closed telnet
25/tcp closed smtp
53/tcp closed domain
80/tcp closed http
...
3389/tcp closed ms-wbt-server
Unlike the default output, --top-ports with a small number lists closed ports too, because there are too few to summarise.
11. Show only open ports: --open
$ sudo nmap --top-ports 20 --open 192.168.56.30
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
Cleaner output, especially across a subnet.
12. TCP SYN scan: -sS
$ sudo nmap -sS -p 22,80 192.168.56.10
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
The default as root. Nmap sends a SYN, reads the reply (SYN/ACK open, RST closed) and never completes the handshake. Quieter in application logs, but intrusion detection still sees it.
13. TCP connect scan: -sT
$ nmap -sT -p 22,80 192.168.56.10
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 0.06 seconds
The default without root. Nmap asks the operating system to make full connections, so the target’s services may log them. The port scanning techniques chapter explains each scan type.
14. UDP scan: -sU
$ sudo nmap -sU --top-ports 20 192.168.56.30
PORT STATE SERVICE
53/udp closed domain
67/udp closed dhcps
68/udp open|filtered dhcpc
69/udp closed tftp
123/udp closed ntp
161/udp open snmp
...
Nmap done: 1 IP address (1 host up) scanned in 21.37 seconds
UDP is slow (no handshake), and open|filtered means no reply, so Nmap cannot tell which. Don’t skip it: SNMP on 161 with a default community string is a classic finding.
15. Show why Nmap decided: --reason
$ sudo nmap --reason -p 22,25,3306 192.168.56.10
PORT STATE SERVICE REASON
22/tcp open ssh syn-ack ttl 64
25/tcp closed smtp reset ttl 64
3306/tcp open mysql syn-ack ttl 64
A TTL of 64 usually points to Linux; Windows typically starts at 128.
Service and OS detection: what is running?
16. Service versions: -sV
$ sudo nmap -sV -p 22,80,443,3306,50051 192.168.56.10
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.58 ((Ubuntu))
443/tcp open ssl/http Apache httpd 2.4.58 ((Ubuntu))
3306/tcp open mysql MySQL 8.0.39-0ubuntu0.24.04.2
50051/tcp open unknown
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
...
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
This turns “port 80 is open” into “Apache 2.4.58 is running”, which you can then check against vendor advisories. When Nmap cannot match a service, as with port 50051 here, connect to it manually and look. Treat versions as evidence to verify, not proof: distributions backport fixes without changing the version number.
17. OS detection: -O
$ sudo nmap -O 192.168.56.10
...
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19
Network Distance: 1 hop
It needs one open and one closed port to be reliable, and it is a fingerprint match: read it as “probably”.
18. Aggressive scan: -A
$ sudo nmap -A -p 21,22 192.168.56.30
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 1043 Oct 02 09:14 staff-list.csv
22/tcp open ssh OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
| ssh-hostkey:
| 256 9c:41:2e:7a:58:0d:b3:6f:e1:20:4c:9a:11:7e:c2:58 (ECDSA)
|_ 256 0e:d8:73:15:a4:6b:92:c0:3e:5f:88:21:d7:46:af:13 (ED25519)
...
OS details: Linux 4.15 - 5.19
TRACEROUTE
HOP RTT ADDRESS
1 0.49 ms 192.168.56.30
-A combines -sV, -O, default scripts and traceroute. Here it found anonymous FTP exposing a staff list in one command. It is noisy, so save it for narrowed-down targets.
Nmap Scripting Engine (NSE)
NSE scripts extend Nmap from port scanner to lightweight vulnerability checker. Browse them all in the NSE documentation.
19. Default scripts: -sC
-sC runs Nmap’s default script category (mostly safe, but not guaranteed non-intrusive).
$ sudo nmap -sC -p 80,443 192.168.56.10
PORT STATE SERVICE
80/tcp open http
|_http-title: Acme Fintech Staff Portal
443/tcp open https
| ssl-cert: Subject: commonName=portal.acme-fintech.test
| Not valid before: 2026-01-12T00:00:00
|_Not valid after: 2027-01-12T23:59:59
|_http-title: Acme Fintech Staff Portal
The certificate’s common name just leaked an internal hostname.
20. Named scripts: --script
$ sudo nmap -p 80 --script http-headers,http-methods 192.168.56.10
PORT STATE SERVICE
80/tcp open http
| http-headers:
| Date: Sat, 10 Oct 2026 09:14:02 GMT
| Server: Apache/2.4.58 (Ubuntu)
| Content-Type: text/html; charset=UTF-8
| Connection: close
|
|_ (Request type: HEAD)
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
No security headers and a full server banner: small findings, still reportable.
21. SMB checks on Windows
$ sudo nmap -p 445 --script smb-protocols,smb2-security-mode -Pn 10.10.20.20
PORT STATE SERVICE
445/tcp open microsoft-ds
Host script results:
| smb-protocols:
| dialects:
| 2:0:2
| 2:1:0
| 3:0:0
| 3:0:2
|_ 3:1:1
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled but not required
SMBv1 is absent (good), but signing is not required, which allows relay attacks: a common internal pentest finding.
22. TLS configuration: ssl-enum-ciphers
$ sudo nmap -p 443 --script ssl-enum-ciphers 192.168.56.10
PORT STATE SERVICE
443/tcp open https
| ssl-enum-ciphers:
| TLSv1.2:
| ciphers:
| TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
| TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
| ...
| TLSv1.3:
| ciphers:
| TLS_AKE_WITH_AES_128_GCM_SHA256 (ecdh_x25519) - A
| TLS_AKE_WITH_AES_256_GCM_SHA384 (ecdh_x25519) - A
| ...
|_ least strength: A
A clean result. If you see TLSv1.0 or ciphers graded C or worse, that is a finding.
Speed and output
23. Timing templates: -T
$ sudo nmap -T4 -F 192.168.56.0/24
...
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.61 seconds
-T0 (paranoid) to -T5 (insane). -T4 suits a lab. On client networks, agree speed in the rules of engagement; aggressive timing can knock over fragile devices.
24. Save every format: -oA
$ sudo nmap -sV -oA acme-web 192.168.56.10
$ ls acme-web.*
acme-web.gnmap acme-web.nmap acme-web.xml
$ grep open acme-web.gnmap
Host: 192.168.56.10 () Ports: 22/open/tcp//ssh//OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)/, 80/open/tcp//http//Apache httpd 2.4.58 ((Ubuntu))/, ...
Always save output: .nmap for humans, .xml for other tools, and the grepable format for shell one-liners.
25. A light scan of the public test host
$ nmap -sV -p 22,80,9929,31337 scanme.nmap.org
Starting Nmap 7.95 ( https://nmap.org ) at 2026-10-10 10:41 WAT
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.19s latency).
Other addresses for scanme.nmap.org (not scanned): 2600:3c01::f03c:91ff:fe18:bb2f
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.7 ((Ubuntu))
9929/tcp open nping-echo Nping echo
31337/tcp open tcpwrapped
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Nmap done: 1 IP address (1 host up) scanned in 7.92 seconds
The one internet host you may practise on without asking. Keep scans light, and expect results to change as the Nmap project maintains it.
A sensible order for a real scan
Put the commands together like this on an authorised internal test:
sudo nmap -sn -iL scope.txt -oA 01-discoveryto find live hosts.sudo nmap -p- --open -iL live.txt -oA 02-allportsto find every open TCP port.sudo nmap -sV -sC -p <ports> -iL live.txt -oA 03-serviceson what you found.sudo nmap -sU --top-ports 50 -iL live.txt -oA 04-udpfor the UDP basics.- Targeted
--scriptruns on interesting services.
That sequence mirrors the discovery phase in NIST SP 800-115, the classic technical guide to security testing. Nmap only finds doors; deciding which ones matter is the tester’s job. For the full picture of where scanning fits, see how to become a penetration tester and our beginner’s penetration testing toolkit.
FAQ
Is Nmap legal? The tool is legal. Using it against systems you do not own or have permission to test may not be. Get written permission first, every time.
Why does my scan show different results without sudo?
Without root privileges Nmap cannot craft raw packets, so it uses connect scans, cannot do ARP discovery, and refuses to run OS detection (-O) without root.
What does “filtered” mean? Nmap got no reply, or an ICMP “administratively prohibited” message, usually because a firewall dropped the probe. It cannot tell whether a service is behind it.