Back to Blog
Tools8 min23,184 views

Top 10 Nmap Commands Every Hacker Should Know

?

Top 10 Nmap Commands Every Hacker Should Know

Nmap (Network Mapper) is the most popular network scanning tool used by security professionals worldwide. Here are the top 10 commands you need to master.

1. Basic Scan

nmap 192.168.1.1

Scans the top 1000 most common ports on the target.

2. Scan Specific Ports

nmap -p 22,80,443,3306 192.168.1.1

Only scan the specified ports.

3. Scan All Ports

nmap -p- 192.168.1.1

Scans all 65,535 TCP ports. Takes longer but finds hidden services.

4. Service Version Detection

nmap -sV 192.168.1.1

Identifies the version of services running on open ports. Essential for finding vulnerable versions!

5. OS Detection

nmap -O 192.168.1.1

Attempts to identify the operating system of the target.

6. Aggressive Scan

nmap -A 192.168.1.1

Combines OS detection, version detection, script scanning, and traceroute.

7. Stealth SYN Scan

sudo nmap -sS 192.168.1.1

Half-open scan that's harder to detect. Requires root privileges.

8. UDP Scan

sudo nmap -sU --top-ports 100 192.168.1.1

Scans UDP ports. Many services like DNS, SNMP, DHCP use UDP.

9. Vulnerability Scan

nmap --script=vuln 192.168.1.1

Runs vulnerability detection scripts against the target.

10. Network Sweep

nmap -sn 192.168.1.0/24

Discovers live hosts on a network without port scanning.

Pro Tips

  • Use -T4 for faster scans on reliable networks

  • Save results with -oN output.txt or -oX output.xml

  • Combine options: nmap -sV -sC -O -T4 target

Conclusion

Master these commands and you'll be able to efficiently map any network. Remember to always scan only systems you have permission to test!