KB / Статті / Nmap: повний гайд по розвідці мережі
UA EN

Nmap: Complete Network Reconnaissance Guide

✍ admin 📅 13.06.2026 👁 119 переглядів

Why Nmap?

Nmap (Network Mapper) is the standard reconnaissance tool in any pentest and CTF. It allows you to:

  • identify live hosts on the network
  • find open ports
  • determine service versions
  • detect the operating system
  • run scripts for additional information

Basic Syntax

nmap [options] <target>

# Target can be:
nmap 192.168.1.1
nmap 192.168.1.0/24
nmap 192.168.1.1-50
nmap scanme.nmap.org

Scan Types

TCP SYN scan (Half-open) — most common

nmap -sS 192.168.1.1

Sends SYN, waits for SYN-ACK (port open) or RST (closed). Does not complete the handshake — less noisy.

TCP Connect scan

nmap -sT 192.168.1.1

Full TCP handshake. Doesn't require root but is more visible in logs.

UDP scan

nmap -sU 192.168.1.1

Slower, but important — DNS (53), SNMP (161), DHCP (67/68) are often on UDP.

Skip host discovery (no ping)

nmap -Pn 192.168.1.1

Useful when a host blocks ICMP but ports are open.

Port Selection

# Top 1000 ports (default)
nmap 192.168.1.1

# All 65535 ports
nmap -p- 192.168.1.1

# Specific ports
nmap -p 22,80,443,8080 192.168.1.1

# Range
nmap -p 1-1000 192.168.1.1

# Top N most common
nmap --top-ports 100 192.168.1.1

Service Versions and OS Detection

# Service versions
nmap -sV 192.168.1.1

# OS detection (requires root)
nmap -O 192.168.1.1

# Aggressive scan (sV + O + scripts + traceroute)
nmap -A 192.168.1.1

NSE Scripts

NSE (Nmap Scripting Engine) is a powerful scripting system for extended analysis.

# Run default scripts
nmap -sC 192.168.1.1

# Specific script
nmap --script=http-title 192.168.1.1

# Script category
nmap --script=vuln 192.168.1.1
nmap --script=auth 192.168.1.1
nmap --script=discovery 192.168.1.1

# Multiple scripts
nmap --script=http-enum,http-headers 192.168.1.1

# SMB enumeration
nmap --script=smb-enum-shares,smb-enum-users -p 445 192.168.1.1

# Check for known vulnerabilities
nmap --script=vuln 192.168.1.1

Speed and Timing

# -T0 Paranoid (very slow, for IDS evasion)
# -T1 Sneaky
# -T2 Polite
# -T3 Normal (default)
# -T4 Aggressive (CTF standard)
# -T5 Insane (may miss results)

nmap -T4 192.168.1.1

Typical CTF Workflow

# 1. Quick scan of all ports
nmap -p- --min-rate 5000 -T4 <IP> -oN ports.txt

# 2. Detailed scan of discovered ports
ports=$(grep ^[0-9] ports.txt | cut -d'/' -f1 | tr '
' ',' | sed 's/,$//')
nmap -sC -sV -p$ports <IP> -oN detailed.txt

# 3. Review results
cat detailed.txt

Saving Results

nmap -oN output.txt     # normal text
nmap -oX output.xml     # XML
nmap -oG output.gnmap   # grep-friendly
nmap -oA output         # all three formats at once

Useful Combinations

# Full host reconnaissance
nmap -sC -sV -O -p- -T4 192.168.1.1

# Scan subnet for live hosts
nmap -sn 192.168.1.0/24

# Quiet scan (no ping, no DNS)
nmap -Pn -n -sS 192.168.1.1

# Through proxychains (for pivot)
proxychains nmap -sT -Pn 10.10.10.1
Коментарі (0)
Увійди, щоб залишити коментар.
Коментарів поки немає.
Вперше тут?
Новачок на Bastion?
Почни з гайду користувача.
Відкрити гайд →
?