Skip to content

Nmap: Information Gathering & Vulnerability Scanning

Docs: nmap.org/book/inst-macosx.html

Installation (macOS):

brew install nmap

Installation (Linux, enum4linux, used later):

sudo apt install enum4linux


1. Host Discovery

Before scanning ports, figure out which hosts on the network are actually alive.

Scan Type Example Command Purpose
Host Discovery (generic) nmap -sn TARGET/24 Skips port scanning; determines live hosts using ICMP/ARP/TCP probes as appropriate. Modern replacement for the deprecated -sP flag.
ARP Scan sudo nmap -PR -sn TARGET/24 Sends ARP requests — most reliable method, but only works on the local subnet (Layer 2).
ICMP Echo Scan sudo nmap -PE -sn TARGET/24 Classic ICMP "ping." Often blocked by firewalls.
ICMP Timestamp Scan sudo nmap -PP -sn TARGET/24 ICMP Timestamp Request — bypasses filters that block Echo specifically.
ICMP Address Mask Scan sudo nmap -PM -sn TARGET/24 ICMP Address Mask Request — another ICMP variant for filter evasion.
TCP SYN Ping Scan sudo nmap -PS22,80,443 -sn TARGET/30 Sends TCP SYN to specified ports; any response (SYN/ACK or RST) confirms the host is up.
TCP ACK Ping Scan sudo nmap -PA22,80,443 -sn TARGET/30 Sends TCP ACK to specified ports — useful when stateless filters block only inbound SYNs.
UDP Ping Scan sudo nmap -PU53,161,162 -sn TARGET/30 Sends UDP probes; an ICMP "port unreachable" reply confirms the host is alive.

Reverse DNS (rDNS): the process of resolving an IP address back to a hostname — useful during host discovery to identify what a live IP actually belongs to.


2. Port Scanning

Once live hosts are known, determine which ports/services are open.

Core Scan Types

Port Scan Type Example Command Purpose
TCP Connect Scan nmap -sT TARGET Uses the OS's normal networking stack to complete a full TCP three-way handshake. No root required, but noisier/more detectable.
TCP SYN Scan sudo nmap -sS TARGET "Half-open" scan — sends SYN, reads the response, but never completes the handshake. Faster and stealthier than -sT. Requires root (raw sockets).
UDP Scan sudo nmap -sU -p 53 TARGET Scans UDP-based services (DNS, SMTP, DHCP, etc.). Slower than TCP scans since UDP has no handshake to confirm state.

Stealth / Evasion Scan Types

Port Scan Type Command Purpose
TCP FIN Scan sudo nmap -sF TARGET Sends a FIN packet. Closed ports reply RST; no reply implies the port may be open. Useful when SYN scans are filtered.
TCP Null Scan sudo nmap -sN TARGET Sends packets with no flags set — slips past stateless filters/IDS that only inspect for SYN packets.
TCP Xmas Scan sudo nmap -sX TARGET Sets FIN, PSH, and URG flags simultaneously ("lit up like a Christmas tree") — relies on RFC-compliant RST responses from closed ports.
TCP Maimon Scan sudo nmap -sM TARGET Sends FIN/ACK together — exploits a quirk in some BSD-derived TCP stacks.
TCP ACK Scan sudo nmap -sA TARGET Sends ACK-only packets. Doesn't reveal open vs. closed — instead maps firewall rule sets (which ports are filtered vs. unfiltered). Useful when a firewall sits in front of the target.
TCP Window Scan sudo nmap -sW TARGET Same probe as ACK scan, but inspects the TCP window size in the response to infer open vs. closed on certain OSes.
Custom TCP Scan sudo nmap --scanflags URGACKPSHRSTSYNFIN TARGET Manually set any combination of TCP flags for a fully custom probe.
Fragment into 8 bytes -f Splits packets into tiny 8-byte fragments to evade packet-inspection firewalls/IDS.
Fragment into 16 bytes -ff Same idea as -f, using 16-byte fragments instead.

Spoofing & Decoys

Technique Command Purpose
Spoofed Source IP nmap -S SPOOFED_IP TARGET Sends packets with a forged source IP to obscure the real scanner (you won't see the responses).
Spoofed MAC Address --spoof-mac SPOOFED_MAC Forges the source MAC on the local segment to hide the real scanning machine.
Decoy Scan nmap -D DECOY_IP,ME TARGET Mixes real traffic with spoofed decoy source IPs so the target sees many "attackers" at once.
Idle (Zombie) Scan sudo nmap -sI ZOMBIE_IP TARGET Uses a third-party "zombie" host's IP ID sequence to scan a target without ever exposing your own IP.

Port Selection & Scan Behavior

Option Purpose
-p- Scan all ports (1–65535)
-p1-1023 Scan ports 1 to 1023
-F Scan the 100 most common ports (fast mode)
-r Scan ports in consecutive order (disables randomization)
-T<0-5> Timing template (see below)
--max-rate=50 Cap scan rate at ≤ 50 packets/sec
--min-rate=15 Enforce scan rate at ≥ 15 packets/sec
--min-parallelism=100 Keep at least 100 probes in flight in parallel

Timing Templates (-T 0–5)

Template Name Behavior
-T0 Paranoid Very slow — IDS evasion
-T1 Sneaky Quite slow — IDS evasion
-T2 Polite ~10x slower than default; reduces bandwidth use
-T3 Normal Default — dynamic timing based on target responsiveness
-T4 Aggressive Assumes a fast, reliable network; may overwhelm targets
-T5 Insane Very aggressive; likely to overwhelm targets or miss open ports

3. Service, Version & OS Detection

Option Meaning
-sV Determine service/version info on open ports
-sV --version-light Try the most likely probes only (faster, ~2 probes)
-sV --version-all Try all available probes (thorough, up to 9 probes)
-O Detect the target's operating system (uppercase O, as in "OS")
--traceroute Run a traceroute to the target
--script=SCRIPTS Run specified Nmap Scripting Engine (NSE) scripts
-sC or --script=default Run the default set of NSE scripts
-A Aggressive scan — equivalent to -sV -O -sC --traceroute

Example — OS detection:

sudo nmap -sS -O MACHINE_IP

Example — targeted NSE script:

sudo nmap -sS -n --script "http-date" TARGET


4. Output Formats

Option Purpose
-oN Save output in normal (human-readable) format
-oG Save output in grepable format
-oX Save output in XML format
-oA Save output in all three formats at once: normal, XML, and grepable

5. Output & Diagnostic Options

Option Purpose
--reason Explains how Nmap reached its open/closed/filtered conclusion for each port
-v Verbose output
-vv Very verbose output
-d Enable debugging output
-dd More detailed debugging output

Enumeration

Enumeration is the process of actively extracting detailed information from a target once it's known to be reachable — usernames, groups, shares, services, and the software/OS behind them.

Types of enumeration covered: - Host Enumeration - User Enumeration - Group Enumeration — determines authorization roles in use on the target environment - Network Share Enumeration — identifies systems sharing files/folders/printers, helping build out an internal attack surface - Additional SMB Enumeration — fingerprints applications and OS on a host - Web Page / Web Application Enumeration - Service Enumeration — identifying services running on a remote system (Nmap's core function as a port scanner) - Enumeration via Packet Crafting

SMB Enumeration (via Nmap NSE)

Enumerating SMB users:

nmap --script smb-enum-users.nse TARGET

Enumerating SMB groups:

nmap --script smb-enum-groups.nse --script-args smbusername=vagrant,smbpass=vagrant TARGET

Network share enumeration:

nmap --script smb-enum-shares.nse -p 445 TARGET

Additional SMB enumeration / fingerprinting:

nmap -sC TARGET

Enumeration with enum4linux

Enum4linux enumerates information from Windows and Samba systems.

Reference: Portcullis Labs — enum4linux

enum4linux 192.168.88.251

Enumeration with smbclient

Docs: samba.org — smbclient

smbclient -L \\192.168.88.251

Web Page / Web Application Enumeration

nmap -sV --script=http-enum -p 80 192.168.88.251

Service Enumeration (process listing via SMB)

nmap --script smb-enum-processes.nse --script-args smbusername=<username>,smbpass=<password> -p445 <host>

Enumeration via Packet Crafting (Scapy)

Scapy documentation — a powerful interactive packet manipulation library in Python.

sudo scapy

Craft a simple ICMP packet:

send(IP(dst="192.168.88.251")/ICMP()/"malicious_payload")

Automated Discovery — Gobuster Fundamentals

Gobuster

Gobuster is an open-source enumeration tool written in Go. It supports multiple modes:

  • dir — directory/file enumeration
  • dns — DNS subdomain enumeration
  • vhost — virtual host enumeration

Pre-installed on the AttackBox and included by default in Kali Linux.

gobuster --help
Shows available commands and global flags.

Global Flags

Flag Description
-t / --threads Number of concurrent threads (default: 10). Increase for faster scans.
-w / --wordlist Path to the wordlist file. Required for all modes.
-o / --output Write results to a file instead of stdout.
--delay Wait time between requests — useful against rate-limited servers.

Wordlists

A good wordlist is critical. SecLists is the most widely used collection and is pre-installed on the AttackBox at /usr/share/wordlists/SecLists/.

For directory enumeration, these cover most scenarios: - Discovery/Web-Content/common.txt - Discovery/Web-Content/directory-list-2.3-medium.txt


dir Mode — Directory & File Brute-Forcing

Brute-forces directories and files on a web server.

Basic syntax:

gobuster dir -u "http://TARGET_IP" -w /path/to/wordlist

  • -u — target URL Gobuster runs discovery against (required)
  • -w — wordlist file of directory/file names to try (required)

Omitting either flag results in an error.

Additional dir Mode Flags

Flag Description
-x / --extensions File extensions to search for (e.g., -x .php,.txt,.js)
-r / --followredirect Follow HTTP redirects
-k / --no-tls-validation Skip TLS certificate verification (useful in lab environments)
-s / --status-codes Only show specific status codes (e.g., -s 200,301)

dns Mode — Subdomain Enumeration

A subdomain is resolved through DNS. For example, blog.example.thm is a DNS record that points to an IP address.

The dns mode brute-forces subdomains by trying each wordlist entry as a prefix to a target domain, then checking whether it resolves.

Example:

gobuster dns -d example.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --wildcard

Useful dns Mode Flags

Flag Description
-d / --domain The target domain to enumerate
-i / --show-ips Show the IP addresses that subdomains resolve to
-r / --resolver Use a custom DNS server for lookups
--wildcard Process wildcard DNS responses instead of filtering them out

vhost Mode — Virtual Host Enumeration

A virtual host (vhost) is resolved by the web server, not DNS. Multiple sites can run on the same IP address, with the server using the Host: HTTP header to decide which site to serve. Gobuster brute-forces this by sending requests to a single IP with different Host header values from the wordlist.

Example:

gobuster vhost -u "http://10.114.130.141" --domain example.thm -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt --append-domain --exclude-length 250-320

Useful vhost Mode Flags

Flag Description
-u / --url The target URL/IP to send requests to
--domain The base domain to use with --append-domain
--append-domain Appends the base domain to each wordlist entry (e.g., turns admin into admin.example.thm)
--exclude-length Excludes responses of a given byte-length range (e.g., 250-320) — filters out the default "not found" page that would otherwise flood results with false positives
-r / --followredirect Follow HTTP redirects
-k / --no-tls-validation Skip TLS certificate verification (useful in lab environments)