nmap Command in Linux with Practical Examples

By 

•

Updated on

•

13 min read

nmap Command in Linux

When you need to see which hosts are online, which ports are open, or which service is listening on a remote system, nmap is usually the first tool to reach for. It is widely used for network inventory, service discovery, troubleshooting, and security reviews.

The nmap command can also detect service versions, guess the remote operating system, and run scripts for deeper checks. This guide explains the most useful nmap options in Linux through practical examples.

Warning
Scan only systems and networks you own or have permission to test. Unauthorized scanning can trigger alerts and may violate local law or policy.

nmap Command Syntax

Use the following syntax when running nmap:

txt
nmap [OPTIONS] TARGET...
  • OPTIONS - Scan type, host discovery, output, and detection flags such as -sn, -Pn, -sV, or -p.
  • TARGET - One or more IP addresses, hostnames, CIDR ranges, or target lists.

Installing Nmap

Nmap is available on all major operating systems, including Linux, BSD, macOS, and Windows.

If you prefer a GUI, Nmap also ships with Zenmap .

Official packages and installers are available from the Nmap download page .

Ubuntu, Debian, and Derivatives

Nmap is available from the default Ubuntu and Debian repositories. To install it, run:

Terminal
sudo apt update
sudo apt install nmap

Fedora, RHEL, and Derivatives

On Fedora and other Red Hat derivatives, run:

Terminal
sudo dnf install nmap

macOS

macOS users can install Nmap by downloading the “.dmg” installation package from the Nmap site or via Homebrew:

Terminal
brew install nmap

Windows

The easiest way to install Nmap on Windows is to download and run the installer from the official site.

You can run it from Command Prompt, PowerShell, or Zenmap. For more details, check the post-install usage instructions .

Run a Basic nmap Scan

Nmap is typically used to audit network security, map networks, identify open ports, and search for online devices. For quick single-port checks or simple TCP/UDP tests, netcat is a lightweight alternative.

The simplest scan targets a single host without any extra options:

Terminal
nmap scanme.nmap.org

When you run nmap as a regular user without raw packet privileges, it falls back to a TCP connect scan (-sT). That means Nmap asks the operating system to complete the TCP connection instead of crafting raw SYN packets itself.

The output includes the responsive host, latency, and the ports Nmap found open or filtered:

output
Starting Nmap 7.98 ( https://nmap.org ) at 2026-10-01 19:29 +0000
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.20s latency).
Not shown: 993 closed tcp ports (conn-refused)
PORT     STATE    SERVICE
22/tcp   open     ssh
80/tcp   open     http
135/tcp  filtered msrpc
139/tcp  filtered netbios-ssn
445/tcp  filtered microsoft-ds
9090/tcp open     zeus-admin
9929/tcp open     nping-echo

Nmap done: 1 IP address (1 host up) scanned in 10.09 seconds

In this example, Nmap reports 22/tcp for SSH and 80/tcp for HTTP as open. Filtering prevented Nmap from determining whether the filtered ports are open. The “Not shown” line tells you that the other 993 scanned ports were closed and were left out of the list. The conn-refused reason confirms that this was a TCP connect scan.

The SERVICE column is only a guess based on the port number. Port 9090 shows zeus-admin because that is the registered name for the port, not because Nmap detected that service. To find out what is really listening, use version detection with -sV.

When to Use sudo nmap

The most common follow-up question is when to run sudo nmap. On Linux, privileged scans allow Nmap to use raw packets, which enables SYN scanning (-sS) and some advanced detection features.

Run this command to use the default privileged TCP SYN scan:

Terminal
sudo nmap 192.168.10.121

With sudo, Nmap usually switches to SYN scan (-sS). This is generally faster and lighter than a full TCP connect scan. Nmap sends a SYN packet and reads the reply, but it never completes the connection.

If you want to be explicit, specify the scan type directly:

Terminal
sudo nmap -sS 192.168.10.121

Use -v or -vv for more detailed progress information:

Terminal
sudo nmap -vv 192.168.10.121

To perform a UDP scan, run nmap as root and add -sU:

Terminal
sudo nmap -sU 192.168.10.121

UDP scans are much slower than TCP scans. Open and filtered UDP ports rarely send a reply, so Nmap waits for a timeout and retransmits the probe. Closed ports reply with an ICMP “port unreachable” message, but Linux and many other systems rate limit those messages, often to about one per second. For that reason, it is better to target only the ports you care about.

Nmap also supports IPv6 targets. To scan an IPv6 host, use -6:

Terminal
sudo nmap -6 fd12:3456:789a:1::1

Specify Target Hosts

Nmap treats every non-option argument as a target host.

Tip
Arguments that begin with - or -- are treated as options.

The simplest form is to pass one or more IP addresses or hostnames:

Terminal
nmap 192.168.10.121 host.to.scan

Use CIDR notation to scan a network range:

Terminal
nmap 192.168.10.0/24

You can also use octet ranges. This example scans 192.168.10.1, 192.168.11.1, and 192.168.12.1:

Terminal
nmap 192.168.10-12.1

Commas let you define multiple values in the same octet:

Terminal
nmap 192.168.10,11,12.1

You can combine these forms in one command:

Terminal
nmap 10.8-10.10,11,12.0/28 192.168.1-2.100,101

If you want to confirm the target list before scanning, use -sL:

Terminal
nmap -sL 10.8-10.10,11,12.0/28 192.168.1-2.100,101

This lists the targets without performing a scan, which is useful when you are working with a large or complex range.

To exclude one or more hosts from a range, use --exclude:

Terminal
nmap 10.8-10.10,11,12.0/28 --exclude 10.10.12.12

Scan Specific Ports

By default, Nmap scans the 1000 most popular ports for each protocol. These ports are not the first 1000 consecutive ports, but the 1000 ports that are most often found open, based on Nmap’s own statistics.

To scan for all ports from 1 through 65535, use the -p- option:

Terminal
nmap -p- 192.168.10.121

If you want a quicker scan, use -F to scan only the 100 most common ports:

Terminal
nmap -F 192.168.10.121

The --top-ports option lets you pick the number yourself. The following command scans the 20 most common ports:

Terminal
nmap --top-ports 20 192.168.10.121

Each port can be in one of the following states:

  • open - A service on the target accepted the connection or probe.
  • closed - The host responded, but nothing is listening on that port.
  • filtered - A firewall, packet filter, or network rule prevented Nmap from confirming the port state.
  • unfiltered - The port is reachable, but Nmap cannot tell whether it is open or closed. You will see this state only with the ACK scan (-sA).
  • open|filtered - Nmap received no reply, so the port is either open or filtered. This is the most common result for UDP ports.

To hide closed and filtered ports, add --open. Nmap also shows open|filtered and unfiltered ports, so the result is not limited to confirmed open ports:

Terminal
nmap --open 192.168.10.121

Ports and port ranges are specified with -p.

To scan only port 443, run:

Terminal
nmap -p 443 192.168.10.121

To scan multiple ports, separate them with commas:

Terminal
nmap -p 80,443 192.168.10.121

Use a dash for ranges. This example scans UDP ports 1 through 1024:

Terminal
sudo nmap -sU -p 1-1024 192.168.10.121

You can combine ranges and individual ports:

Terminal
nmap -p 1-1024,8080,9000 192.168.10.121

You can also use service names. For example, this scans the SSH port:

Terminal
nmap -p ssh 192.168.10.121

Discover Live Hosts with -sn

To perform host discovery without a port scan, use -sn:

Terminal
sudo nmap -sn 192.168.10.0/24

This tells Nmap to find which hosts are up and skip the port scan stage. It is useful when you want a fast inventory of live systems on a subnet before deciding what to scan next.

When you run it with sudo on a local Ethernet network, Nmap uses ARP requests to find hosts. ARP replies are hard to block on the same network, so this is the most reliable way to list devices on your LAN. As a regular user, Nmap tries TCP connections to ports 80 and 443. A closed port can still reveal a live host through a connection refusal, but Nmap can miss a host if probes to both ports are silently filtered.

In older Nmap releases, -sn was called -sP. You will still find nmap -sP in many guides, and current versions accept it, but -sn is the option to use.

Skip Host Discovery with -Pn

By default, Nmap performs host discovery first and scans only hosts it believes are online. That behavior is efficient, but it can miss hosts when firewalls drop discovery probes.

Use -Pn to skip host discovery and treat every target as online:

Terminal
sudo nmap -Pn 192.168.10.121

This is especially useful when a host blocks ping or other discovery probes but still has open ports you want to test. The tradeoff is speed: -Pn can make large scans much slower because Nmap attempts the requested scan against every target you specify.

If you see guidance online for -P0 or -PN, that refers to older Nmap syntax. The current option is -Pn.

Disable DNS Name Resolution

Nmap’s default behavior is to perform reverse-DNS resolution for each discovered host, which increases the scan time.

When scanning large ranges, disabling DNS lookups can make the scan noticeably faster. Use -n:

Terminal
sudo nmap -n 192.168.10.0/24

Control Scan Timing

Nmap uses timing templates to decide how fast it sends probes and how long it waits for replies. Set a template with -T followed by a number from 0 to 5:

  • -T0 and -T1 (paranoid, sneaky) - Very slow scans meant to avoid intrusion detection systems.
  • -T2 (polite) - Slows down the scan to use less bandwidth and fewer target resources.
  • -T3 (normal) - The default.
  • -T4 (aggressive) - Faster scan for reliable, modern networks.
  • -T5 (insane) - The fastest template, which may sacrifice accuracy.

On a local network or a decent broadband connection, -T4 is a good default. The Nmap documentation itself recommends it:

Terminal
sudo nmap -T4 192.168.10.0/24

If a scan starts reporting ports as filtered that you know are open, drop back to -T3. Slow or busy links can lose probes when Nmap sends them too quickly.

Detect Services, Versions, and OS Details

To identify the service and version behind an open port, use -sV:

Terminal
sudo nmap -sV scanme.nmap.org

This helps when the port number alone is not enough, especially if a service is running on a non-standard port.

output
...
PORT     STATE    SERVICE      VERSION
22/tcp   open     ssh          OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp   open     http         Apache httpd 2.4.7 ((Ubuntu))
135/tcp  filtered msrpc
139/tcp  filtered netbios-ssn
445/tcp  filtered microsoft-ds
9090/tcp open     zeus-admin?
9929/tcp open     nping-echo   Nping echo
...
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

The VERSION column now shows the software behind each open port, such as OpenSSH on port 22 and Apache on port 80. A question mark after the service name, as in zeus-admin?, means Nmap could not identify the service through its probes and fell back to the port’s registered name. If a service responds but Nmap cannot identify it, Nmap prints a fingerprint and a submission URL.

To attempt operating system detection, use -O:

Terminal
sudo nmap -O scanme.nmap.org

If Nmap can fingerprint the remote system, the output looks similar to this:

output
...
Device type: general purpose
Running: Linux 5.X
OS CPE: cpe:/o:linux:linux_kernel:5
OS details: Linux 5.0 - 5.4
Network Distance: 18 hops

OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.47 seconds

OS detection works best when Nmap finds at least one open and one closed TCP port. When the results are uncertain, Nmap prints its best guesses with a percentage next to each one.

If you want OS detection, version detection, default scripts, and traceroute in one command, use -A:

Terminal
sudo nmap -A 192.168.10.121

Aggressive scan mode is useful during focused testing, but it is heavier and slower than a basic scan. It is usually better to start small and add options as needed.

Save nmap Output

By default, Nmap prints the information to standard output (stdout).

If you scan a large network or need to keep the results, save the output to a file.

To save the normal human-readable output, use -oN:

Terminal
sudo nmap -sU -p 1-1024 192.168.10.121 -oN output.txt

To save XML output for later parsing or import into other tools, use -oX:

Terminal
sudo nmap -sU -p 1-1024 192.168.10.121 -oX output.xml

If you want normal, XML, and grepable output files in one run, use -oA with a base filename:

Terminal
sudo nmap -sV 192.168.10.121 -oA scan-results

This creates three files: scan-results.nmap, scan-results.xml, and scan-results.gnmap.

Nmap still supports grepable output with -oG, which can be processed with tools such as grep , awk , and cut . However, the Nmap documentation treats grepable output as deprecated, so XML is the better choice for new automation.

Use the Nmap Scripting Engine

One of the most powerful features of Nmap is its scripting engine. Nmap ships with hundreds of scripts , and you can also write your own scripts in the Lua language.

You can use scripts to gather extra information, test specific services, and automate common checks.

The easiest way to start is with -sC, which runs the default set of scripts. This is the same as --script default. Nmap selects default scripts for speed and usefulness, but includes a few it marks as intrusive, so use -sC only on hosts you have permission to test:

Terminal
sudo nmap -sC -sV scanme.nmap.org

To run a single script, pass its name to --script. The http-title script prints the title of the default page on a web server:

Terminal
nmap -p 80 --script http-title scanme.nmap.org

The script output appears under the port it ran against:

output
PORT   STATE SERVICE
80/tcp open  http
|_http-title: Go ahead and ScanMe!

To see what a script does before you run it, use --script-help:

Terminal
nmap --script-help http-title

The help output includes the script categories. Scripts in the safe category are designed to avoid crashing services, using substantial resources, or exploiting vulnerabilities, but Nmap does not guarantee that they cannot cause problems. Scripts in the intrusive category carry a higher risk of disrupting a target, while vuln scripts check for known vulnerabilities and vary in behavior. Review a script before running it against production systems.

Quick Reference

For a printable quick reference, see the nmap cheatsheet .

TaskCommand
Basic scannmap target
SYN scan as rootsudo nmap -sS target
Scan specific portsnmap -p 22,80,443 target
Scan all portsnmap -p- target
Scan the 100 most common portsnmap -F target
Hide closed and filtered portsnmap --open target
Faster timingsudo nmap -T4 target
Host discovery onlysudo nmap -sn 192.168.10.0/24
Skip host discoverysudo nmap -Pn target
Detect service versionssudo nmap -sV target
OS detectionsudo nmap -O target
Default scriptssudo nmap -sC target
Save normal outputnmap target -oN output.txt
Save all major formatsnmap target -oA scan-results

Troubleshooting

Host appears down, but you know it is online
Try -Pn to skip host discovery. Some firewalls drop the probes Nmap uses to decide whether a host is up.

UDP scan is taking too long
Limit the ports with -p instead of scanning large UDP ranges. UDP scans are slower and often return less clear feedback than TCP scans.

DNS lookups are slowing the scan
Add -n to skip reverse DNS resolution, especially when scanning large networks.

You are not seeing SYN scan behavior
Run the command with sudo or specify -sS. Without raw packet privileges, Nmap falls back to TCP connect scan.

Conclusion

The nmap command is one of the most useful Linux tools for host discovery, port scanning, and service detection. If you want a lighter tool for quick socket tests, see netcat next.

Linuxize Weekly Newsletter

A quick weekly roundup of new tutorials, news, and tips.

About the authors

Dejan Panovski

Dejan Panovski

Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.

View author page