Port Scanning

Basic port scanning commands.

Network Port Scanning Recommendation

  1. Create active host list

    1. Scan most used 1000 TCP port

    2. Scan most used 100 UDP Port

  2. Deep Scan Active Hosts

    1. Scan all TCP ports from active host list with service detection

Create Active Host List

mkdir -p $PROJECT_DIR/scans/nmap
cd $PROJECT_DIR/scans/nmap/

TCP Discovery Scan

sudo nmap -sS --top-ports 1000 -iL $TARGETS -oA Nmap_TCP_1000_$(date +"%b-%d-%Y") -Pn -T4 --host-timeout=24h --max-retries=1 --defeat-rst-ratelimit --open --disable-arp-ping

UDP Discovery Scan

sudo nmap -sU --top-ports 100 -iL $TARGETS -oA Nmap_UDP_100_$(date +"%b-%d-%Y") -Pn -T4 --host-timeout=24h --max-retries=1 --defeat-rst-ratelimit --open --disable-arp-ping
setvar NMAP_UDP_NMAP_OUTPUT Nmap_UDP_100_*.nmap(N:A)
setvar NMAP_UDP_GNMAP_OUTPUT Nmap_UDP_100_*.gnmap(N:A)
setvar NMAP_UDP_XML_OUTPUT Nmap_UDP_100_*.xml(N:A)

Get Active Hosts from Results

Deep Scan Active Hosts

Extra Options

Scheduled Scans

MassScan

All TCP Scan

Top 100 UDP Scan

Last updated