Learn Nmap from beginner to advanced with practical commands for host discovery, port scanning, service detection, OS detection, NSE scripts, UDP scanning, output formats, troubleshooting, and security assessments.
Author
Abhishek Singh
Published
13 min read
Nmap, short for Network Mapper, is one of the most widely used tools for network discovery, port scanning, service detection, and security assessment.
Whether you're learning VAPT, preparing for a penetration-testing lab, working as a SOC analyst, or simply learning Linux networking, Nmap is one of the first tools you should understand.
This guide starts with the basics and gradually moves toward more advanced Nmap commands.
⚠️ Authorization: Only scan systems, networks, and IP addresses that you own or have explicit permission to test. Use Hackvora labs or your own isolated environment for practice.
What You Will Learn
By the end of this guide, you should understand:
What Nmap is
How Nmap works
Basic Nmap commands
Host discovery
Port scanning
TCP and UDP scanning
Service and version detection
Operating-system detection
NSE scripts
HTTP enumeration
SSH enumeration
SMB enumeration
TLS enumeration
Scan timing
Output formats
Saving scan results
Understanding Nmap results
Building a practical reconnaissance workflow
1. What Is Nmap?
Nmap is an open-source network exploration and security-auditing tool.
It can help identify:
Live hosts
Open ports
Network services
Service versions
Operating-system characteristics
Firewall/filtering behavior
Additional information through NSE scripts
Nmap can scan a single machine or a large authorized network.
It only tells you that Nmap believes an HTTP service is available.
Mistake 3 — Trusting version detection blindly
Version detection is useful, but important findings should be verified.
Mistake 4 — Always using aggressive scans
You don't need:
TERMINAL OUTPUT
nmap -A -T5 -p- ...
for every situation.
Start with a focused scan and increase detail when needed.
Mistake 5 — Not saving evidence
Use:
TERMINAL OUTPUT
nmap -oA assessment <TARGET>
when you need to retain results.
Mistake 6 — Ignoring UDP
TCP is not the entire network.
Important services can operate over UDP.
47. Nmap Command Cheat Sheet
Purpose
Command
Basic scan
nmap <TARGET>
Host discovery
nmap -sn <NETWORK>
Skip discovery
nmap -Pn <TARGET>
Single port
nmap -p 22 <TARGET>
Multiple ports
nmap -p 22,80,443 <TARGET>
Port range
nmap -p 1-1000 <TARGET>
All TCP ports
nmap -p- <TARGET>
Fast scan
nmap -F <TARGET>
Top ports
nmap --top-ports 100 <TARGET>
SYN scan
sudo nmap -sS <TARGET>
TCP connect
nmap -sT <TARGET>
UDP scan
sudo nmap -sU <TARGET>
Version detection
nmap -sV <TARGET>
Default scripts
nmap -sC <TARGET>
OS detection
sudo nmap -O <TARGET>
Aggressive scan
nmap -A <TARGET>
No DNS
nmap -n <TARGET>
Verbose
nmap -v <TARGET>
Show open ports
nmap --open <TARGET>
Explain states
nmap --reason <TARGET>
Normal output
nmap -oN scan.txt <TARGET>
XML output
nmap -oX scan.xml <TARGET>
Grepable output
nmap -oG scan.txt <TARGET>
All output formats
nmap -oA scan <TARGET>
IPv6
nmap -6 <TARGET>
Numerical port order
nmap -r <TARGET>
NSE script
nmap --script <SCRIPT> <TARGET>
48. Beginner Practice Challenge
Now practice what you learned.
Use an authorized Hackvora lab target.
Task 1
Discover the host:
TERMINAL OUTPUT
nmap -sn <TARGET>
Task 2
Find the common ports:
TERMINAL OUTPUT
nmap --top-ports 100 <TARGET>
Task 3
Find all TCP ports:
TERMINAL OUTPUT
nmap -p- <TARGET>
Task 4
Identify services:
TERMINAL OUTPUT
nmap -sV <TARGET>
Task 5
Run default scripts:
TERMINAL OUTPUT
nmap -sC <TARGET>
Task 6
Combine service detection and scripts:
TERMINAL OUTPUT
nmap -sC -sV <TARGET>
Task 7
Save your results:
TERMINAL OUTPUT
nmap -oA nmap-practice <TARGET>
49. Intermediate Challenge
After completing the beginner challenge, investigate:
HTTP
SSH
SMB
DNS
TLS
UDP
NSE scripts
scan output
service versions
For example:
TERMINAL OUTPUT
nmap -p 80,443 --script http-title <TARGET>
Then answer:
Which ports are open?
Which services are running?
Which versions were detected?
Which ports use TCP?
Which ports use UDP?
What additional information did NSE provide?
Which findings require manual verification?
50. Advanced Challenge
For advanced learners, focus less on memorizing commands and more on understanding how Nmap works.
Study:
TCP/IP
TCP flags
SYN scanning
UDP behavior
firewalls
packet filtering
service fingerprinting
OS detection
NSE
scan timing
output parsing
network segmentation
defensive detection
The goal is to understand:
TERMINAL OUTPUT
Why did Nmap send this packet?
↓
What response did it receive?
↓
How did Nmap interpret it?
↓
What does the result mean?
↓
What should I investigate next?
51. Most Important Commands to Remember
If you're new to Nmap, start with these:
TERMINAL OUTPUT
nmap <TARGET>
TERMINAL OUTPUT
nmap -sn <NETWORK>
TERMINAL OUTPUT
nmap -p- <TARGET>
TERMINAL OUTPUT
nmap -sV <TARGET>
TERMINAL OUTPUT
nmap -sC -sV <TARGET>
TERMINAL OUTPUT
sudo nmap -O <TARGET>
TERMINAL OUTPUT
sudo nmap -sU <TARGET>
TERMINAL OUTPUT
nmap -oA scan <TARGET>
Once you understand these commands, move into NSE, service-specific enumeration, packet behavior, and defensive analysis.
52. Nmap Learning Path
A good way to learn Nmap is:
TERMINAL OUTPUT
Linux Basics
↓
Networking Basics
↓
TCP/IP
↓
Nmap Basics
↓
Host Discovery
↓
Port Scanning
↓
Service Enumeration
↓
NSE
↓
Web Enumeration
↓
Network Security
↓
VAPT
On Hackvora, Nmap should be treated as a practical skill rather than a list of commands to memorize.
Conclusion
Nmap is one of the most important tools to learn when entering cybersecurity.
But becoming good at Nmap is not about remembering hundreds of flags.
It's about learning how to move from:
TERMINAL OUTPUT
Host
↓
Port
↓
Service
↓
Version
↓
Configuration
↓
Security Impact
↓
Evidence
↓
Remediation
Start with simple scans, understand the results, practice in an authorized sandbox, and gradually move toward deeper service enumeration.
Once you're comfortable with Nmap, the next step is to combine it with your Linux, networking, HTTP, and VAPT knowledge to perform structured security assessments.
Practice responsibly. Scan only systems you are authorized to test.