NMap Cheat Sheet Discovery Flashcards
Skip host discovery (no ping)
nmap -Pn
Disables host discovery; same as nmap -P0
Skip port scan
nmap -sn
List targets to scan
nmap -sL
TCP SYN ping
nmap -PS
TCP ACK ping
nmap -PA
UDP ping
nmap -PU
ICMP echo ping
nmap -PE
ICMP timestamp ping
nmap -PP
ICMP netmask ping
nmap -PM
IP protocol ping
nmap -PO
OS fingerprinting and port scanning
nmap -O
Send packets to remote OS and analyze the response. This is ACTIVE scanning.
Aggressive
nmap -A
OS fingerprinting and port scanning with VULNERABILITY scanning
Also includes a TRACEROUTE and lists possible problems with each scanned port number. Do a -O and -A to see the difference!
IP Protocol Scan
nmap -sO
Major protocols like ICMP, TCP, UDP, IGMP, etc
TCP Connect
nmap -sT
This does leave a record of your activities in target system, but it’s very reliable.
SYN Scanning, Stealth Scan
nmap -sS
Also known as HALF-OPEN scanning. This is the default scan and the most common.
FIN Scan
nmap -sF
Null Scan
nmap -sN
Xmas Scan
nmap -sX
Xmas scan sets Fin, Urg, and Psh, although some utilities turn ALL 6 flags on!
Ping Scan
nmap -sP or -sn
Determines active hosts
Ex: nmap -sP 192.168.3.1-20 will scan 3.1 through 3.20 to see which are up (which reply).
UDP Scan
nmap -sU
Looks for open UDP ports.
ACK Scan
nmap -sA
Used to test your firewall rules.