Nmap: Information Gathering & Vulnerability Scanning
Docs: nmap.org/book/inst-macosx.html
Installation (macOS):
Installation (Linux, enum4linux, used later):
1. Host Discovery
Before scanning ports, figure out which hosts on the network are actually alive.
| Scan Type | Example Command | Purpose |
|---|---|---|
| Host Discovery (generic) | nmap -sn TARGET/24 |
Skips port scanning; determines live hosts using ICMP/ARP/TCP probes as appropriate. Modern replacement for the deprecated -sP flag. |
| ARP Scan | sudo nmap -PR -sn TARGET/24 |
Sends ARP requests — most reliable method, but only works on the local subnet (Layer 2). |
| ICMP Echo Scan | sudo nmap -PE -sn TARGET/24 |
Classic ICMP "ping." Often blocked by firewalls. |
| ICMP Timestamp Scan | sudo nmap -PP -sn TARGET/24 |
ICMP Timestamp Request — bypasses filters that block Echo specifically. |
| ICMP Address Mask Scan | sudo nmap -PM -sn TARGET/24 |
ICMP Address Mask Request — another ICMP variant for filter evasion. |
| TCP SYN Ping Scan | sudo nmap -PS22,80,443 -sn TARGET/30 |
Sends TCP SYN to specified ports; any response (SYN/ACK or RST) confirms the host is up. |
| TCP ACK Ping Scan | sudo nmap -PA22,80,443 -sn TARGET/30 |
Sends TCP ACK to specified ports — useful when stateless filters block only inbound SYNs. |
| UDP Ping Scan | sudo nmap -PU53,161,162 -sn TARGET/30 |
Sends UDP probes; an ICMP "port unreachable" reply confirms the host is alive. |
Reverse DNS (rDNS): the process of resolving an IP address back to a hostname — useful during host discovery to identify what a live IP actually belongs to.
2. Port Scanning
Once live hosts are known, determine which ports/services are open.
Core Scan Types
| Port Scan Type | Example Command | Purpose |
|---|---|---|
| TCP Connect Scan | nmap -sT TARGET |
Uses the OS's normal networking stack to complete a full TCP three-way handshake. No root required, but noisier/more detectable. |
| TCP SYN Scan | sudo nmap -sS TARGET |
"Half-open" scan — sends SYN, reads the response, but never completes the handshake. Faster and stealthier than -sT. Requires root (raw sockets). |
| UDP Scan | sudo nmap -sU -p 53 TARGET |
Scans UDP-based services (DNS, SMTP, DHCP, etc.). Slower than TCP scans since UDP has no handshake to confirm state. |
Stealth / Evasion Scan Types
| Port Scan Type | Command | Purpose |
|---|---|---|
| TCP FIN Scan | sudo nmap -sF TARGET |
Sends a FIN packet. Closed ports reply RST; no reply implies the port may be open. Useful when SYN scans are filtered. |
| TCP Null Scan | sudo nmap -sN TARGET |
Sends packets with no flags set — slips past stateless filters/IDS that only inspect for SYN packets. |
| TCP Xmas Scan | sudo nmap -sX TARGET |
Sets FIN, PSH, and URG flags simultaneously ("lit up like a Christmas tree") — relies on RFC-compliant RST responses from closed ports. |
| TCP Maimon Scan | sudo nmap -sM TARGET |
Sends FIN/ACK together — exploits a quirk in some BSD-derived TCP stacks. |
| TCP ACK Scan | sudo nmap -sA TARGET |
Sends ACK-only packets. Doesn't reveal open vs. closed — instead maps firewall rule sets (which ports are filtered vs. unfiltered). Useful when a firewall sits in front of the target. |
| TCP Window Scan | sudo nmap -sW TARGET |
Same probe as ACK scan, but inspects the TCP window size in the response to infer open vs. closed on certain OSes. |
| Custom TCP Scan | sudo nmap --scanflags URGACKPSHRSTSYNFIN TARGET |
Manually set any combination of TCP flags for a fully custom probe. |
| Fragment into 8 bytes | -f |
Splits packets into tiny 8-byte fragments to evade packet-inspection firewalls/IDS. |
| Fragment into 16 bytes | -ff |
Same idea as -f, using 16-byte fragments instead. |
Spoofing & Decoys
| Technique | Command | Purpose |
|---|---|---|
| Spoofed Source IP | nmap -S SPOOFED_IP TARGET |
Sends packets with a forged source IP to obscure the real scanner (you won't see the responses). |
| Spoofed MAC Address | --spoof-mac SPOOFED_MAC |
Forges the source MAC on the local segment to hide the real scanning machine. |
| Decoy Scan | nmap -D DECOY_IP,ME TARGET |
Mixes real traffic with spoofed decoy source IPs so the target sees many "attackers" at once. |
| Idle (Zombie) Scan | sudo nmap -sI ZOMBIE_IP TARGET |
Uses a third-party "zombie" host's IP ID sequence to scan a target without ever exposing your own IP. |
Port Selection & Scan Behavior
| Option | Purpose |
|---|---|
-p- |
Scan all ports (1–65535) |
-p1-1023 |
Scan ports 1 to 1023 |
-F |
Scan the 100 most common ports (fast mode) |
-r |
Scan ports in consecutive order (disables randomization) |
-T<0-5> |
Timing template (see below) |
--max-rate=50 |
Cap scan rate at ≤ 50 packets/sec |
--min-rate=15 |
Enforce scan rate at ≥ 15 packets/sec |
--min-parallelism=100 |
Keep at least 100 probes in flight in parallel |
Timing Templates (-T 0–5)
| Template | Name | Behavior |
|---|---|---|
-T0 |
Paranoid | Very slow — IDS evasion |
-T1 |
Sneaky | Quite slow — IDS evasion |
-T2 |
Polite | ~10x slower than default; reduces bandwidth use |
-T3 |
Normal | Default — dynamic timing based on target responsiveness |
-T4 |
Aggressive | Assumes a fast, reliable network; may overwhelm targets |
-T5 |
Insane | Very aggressive; likely to overwhelm targets or miss open ports |
3. Service, Version & OS Detection
| Option | Meaning |
|---|---|
-sV |
Determine service/version info on open ports |
-sV --version-light |
Try the most likely probes only (faster, ~2 probes) |
-sV --version-all |
Try all available probes (thorough, up to 9 probes) |
-O |
Detect the target's operating system (uppercase O, as in "OS") |
--traceroute |
Run a traceroute to the target |
--script=SCRIPTS |
Run specified Nmap Scripting Engine (NSE) scripts |
-sC or --script=default |
Run the default set of NSE scripts |
-A |
Aggressive scan — equivalent to -sV -O -sC --traceroute |
Example — OS detection:
Example — targeted NSE script:
4. Output Formats
| Option | Purpose |
|---|---|
-oN |
Save output in normal (human-readable) format |
-oG |
Save output in grepable format |
-oX |
Save output in XML format |
-oA |
Save output in all three formats at once: normal, XML, and grepable |
5. Output & Diagnostic Options
| Option | Purpose |
|---|---|
--reason |
Explains how Nmap reached its open/closed/filtered conclusion for each port |
-v |
Verbose output |
-vv |
Very verbose output |
-d |
Enable debugging output |
-dd |
More detailed debugging output |
Enumeration
Enumeration is the process of actively extracting detailed information from a target once it's known to be reachable — usernames, groups, shares, services, and the software/OS behind them.
Types of enumeration covered: - Host Enumeration - User Enumeration - Group Enumeration — determines authorization roles in use on the target environment - Network Share Enumeration — identifies systems sharing files/folders/printers, helping build out an internal attack surface - Additional SMB Enumeration — fingerprints applications and OS on a host - Web Page / Web Application Enumeration - Service Enumeration — identifying services running on a remote system (Nmap's core function as a port scanner) - Enumeration via Packet Crafting
SMB Enumeration (via Nmap NSE)
Enumerating SMB users:
Enumerating SMB groups:
Network share enumeration:
Additional SMB enumeration / fingerprinting:
Enumeration with enum4linux
Enum4linux enumerates information from Windows and Samba systems.
Reference: Portcullis Labs — enum4linux
Enumeration with smbclient
Docs: samba.org — smbclient
Web Page / Web Application Enumeration
Service Enumeration (process listing via SMB)
nmap --script smb-enum-processes.nse --script-args smbusername=<username>,smbpass=<password> -p445 <host>
Enumeration via Packet Crafting (Scapy)
Scapy documentation — a powerful interactive packet manipulation library in Python.
Craft a simple ICMP packet:
Automated Discovery — Gobuster Fundamentals
Gobuster
Gobuster is an open-source enumeration tool written in Go. It supports multiple modes:
dir— directory/file enumerationdns— DNS subdomain enumerationvhost— virtual host enumeration
Pre-installed on the AttackBox and included by default in Kali Linux.
Shows available commands and global flags.Global Flags
| Flag | Description |
|---|---|
-t / --threads |
Number of concurrent threads (default: 10). Increase for faster scans. |
-w / --wordlist |
Path to the wordlist file. Required for all modes. |
-o / --output |
Write results to a file instead of stdout. |
--delay |
Wait time between requests — useful against rate-limited servers. |
Wordlists
A good wordlist is critical. SecLists is the most widely used collection and is pre-installed on the AttackBox at /usr/share/wordlists/SecLists/.
For directory enumeration, these cover most scenarios:
- Discovery/Web-Content/common.txt
- Discovery/Web-Content/directory-list-2.3-medium.txt
dir Mode — Directory & File Brute-Forcing
Brute-forces directories and files on a web server.
Basic syntax:
-u— target URL Gobuster runs discovery against (required)-w— wordlist file of directory/file names to try (required)
Omitting either flag results in an error.
Additional dir Mode Flags
| Flag | Description |
|---|---|
-x / --extensions |
File extensions to search for (e.g., -x .php,.txt,.js) |
-r / --followredirect |
Follow HTTP redirects |
-k / --no-tls-validation |
Skip TLS certificate verification (useful in lab environments) |
-s / --status-codes |
Only show specific status codes (e.g., -s 200,301) |
dns Mode — Subdomain Enumeration
A subdomain is resolved through DNS. For example, blog.example.thm is a DNS record that points to an IP address.
The dns mode brute-forces subdomains by trying each wordlist entry as a prefix to a target domain, then checking whether it resolves.
Example:
gobuster dns -d example.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --wildcard
Useful dns Mode Flags
| Flag | Description |
|---|---|
-d / --domain |
The target domain to enumerate |
-i / --show-ips |
Show the IP addresses that subdomains resolve to |
-r / --resolver |
Use a custom DNS server for lookups |
--wildcard |
Process wildcard DNS responses instead of filtering them out |
vhost Mode — Virtual Host Enumeration
A virtual host (vhost) is resolved by the web server, not DNS. Multiple sites can run on the same IP address, with the server using the Host: HTTP header to decide which site to serve. Gobuster brute-forces this by sending requests to a single IP with different Host header values from the wordlist.
Example:
gobuster vhost -u "http://10.114.130.141" --domain example.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --append-domain --exclude-length 250-320
Useful vhost Mode Flags
| Flag | Description |
|---|---|
-u / --url |
The target URL/IP to send requests to |
--domain |
The base domain to use with --append-domain |
--append-domain |
Appends the base domain to each wordlist entry (e.g., turns admin into admin.example.thm) |
--exclude-length |
Excludes responses of a given byte-length range (e.g., 250-320) — filters out the default "not found" page that would otherwise flood results with false positives |
-r / --followredirect |
Follow HTTP redirects |
-k / --no-tls-validation |
Skip TLS certificate verification (useful in lab environments) |