nmap Command in Linux with Practical Examples

When you need to see which hosts are online, which ports are open, or which service is listening on a remote system, nmap is usually the first tool to reach for. It is widely used for network inventory, service discovery, troubleshooting, and security reviews.
The nmap command can also detect service versions, guess the remote operating system, and run scripts for deeper checks. This guide explains the most useful nmap options in Linux through practical examples.
nmap Command Syntax
Use the following syntax when running nmap:
nmap [OPTIONS] TARGET...OPTIONS- Scan type, host discovery, output, and detection flags such as-sn,-Pn,-sV, or-p.TARGET- One or more IP addresses, hostnames, CIDR ranges, or target lists.
Installing Nmap
Nmap is available on all major operating systems, including Linux, BSD, macOS, and Windows.
If you prefer a GUI, Nmap also ships with Zenmap .
Official packages and installers are available from the Nmap download page .
Ubuntu, Debian, and Derivatives
Nmap is available from the default Ubuntu and Debian repositories. To install it, run:
sudo apt update
sudo apt install nmapFedora, RHEL, and Derivatives
On Fedora and other Red Hat derivatives, run:
sudo dnf install nmapmacOS
macOS users can install Nmap by downloading the “.dmg” installation package from the Nmap site or via Homebrew:
brew install nmapWindows
The easiest way to install Nmap on Windows is to download and run the installer from the official site.
You can run it from Command Prompt, PowerShell, or Zenmap. For more details, check the post-install usage instructions .
Run a Basic nmap Scan
Nmap is typically used to audit network security, map networks, identify open ports, and search for online devices. For quick single-port checks or simple TCP/UDP tests, netcat
is a lightweight alternative.
The simplest scan targets a single host without any extra options:
nmap scanme.nmap.orgWhen you run nmap as a regular user without raw packet privileges, it falls back to a TCP connect scan (-sT). That means Nmap asks the operating system to complete the TCP connection instead of crafting raw SYN packets itself.
The output includes the responsive host, latency, and the ports Nmap found open or filtered:
Starting Nmap 7.98 ( https://nmap.org ) at 2026-10-01 19:29 +0000
Nmap scan report for scanme.nmap.org (45.33.32.156)
Host is up (0.20s latency).
Not shown: 993 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
9090/tcp open zeus-admin
9929/tcp open nping-echo
Nmap done: 1 IP address (1 host up) scanned in 10.09 secondsIn this example, Nmap reports 22/tcp for SSH and 80/tcp for HTTP as open. Filtering prevented Nmap from determining whether the filtered ports are open. The “Not shown” line tells you that the other 993 scanned ports were closed and were left out of the list. The conn-refused reason confirms that this was a TCP connect scan.
The SERVICE column is only a guess based on the port number. Port 9090 shows zeus-admin because that is the registered name for the port, not because Nmap detected that service. To find out what is really listening, use version detection with -sV.
When to Use sudo nmap
The most common follow-up question is when to run sudo nmap. On Linux, privileged scans allow Nmap to use raw packets, which enables SYN scanning (-sS) and some advanced detection features.
Run this command to use the default privileged TCP SYN scan:
sudo nmap 192.168.10.121With sudo, Nmap usually switches to SYN scan (-sS). This is generally faster and lighter than a full TCP connect scan. Nmap sends a SYN packet and reads the reply, but it never completes the connection.
If you want to be explicit, specify the scan type directly:
sudo nmap -sS 192.168.10.121Use -v or -vv for more detailed progress information:
sudo nmap -vv 192.168.10.121To perform a UDP scan, run nmap as root and add -sU:
sudo nmap -sU 192.168.10.121UDP scans are much slower than TCP scans. Open and filtered UDP ports rarely send a reply, so Nmap waits for a timeout and retransmits the probe. Closed ports reply with an ICMP “port unreachable” message, but Linux and many other systems rate limit those messages, often to about one per second. For that reason, it is better to target only the ports you care about.
Nmap also supports IPv6 targets. To scan an IPv6 host, use -6:
sudo nmap -6 fd12:3456:789a:1::1Specify Target Hosts
Nmap treats every non-option argument as a target host.
- or -- are treated as options.The simplest form is to pass one or more IP addresses or hostnames:
nmap 192.168.10.121 host.to.scanUse CIDR notation to scan a network range:
nmap 192.168.10.0/24You can also use octet ranges. This example scans 192.168.10.1, 192.168.11.1, and 192.168.12.1:
nmap 192.168.10-12.1Commas let you define multiple values in the same octet:
nmap 192.168.10,11,12.1You can combine these forms in one command:
nmap 10.8-10.10,11,12.0/28 192.168.1-2.100,101If you want to confirm the target list before scanning, use -sL:
nmap -sL 10.8-10.10,11,12.0/28 192.168.1-2.100,101This lists the targets without performing a scan, which is useful when you are working with a large or complex range.
To exclude one or more hosts from a range, use --exclude:
nmap 10.8-10.10,11,12.0/28 --exclude 10.10.12.12Scan Specific Ports
By default, Nmap scans the 1000 most popular ports for each protocol. These ports are not the first 1000 consecutive ports, but the 1000 ports that are most often found open, based on Nmap’s own statistics.
To scan for all ports from 1 through 65535, use the -p- option:
nmap -p- 192.168.10.121If you want a quicker scan, use -F to scan only the 100 most common ports:
nmap -F 192.168.10.121The --top-ports option lets you pick the number yourself. The following command scans the 20 most common ports:
nmap --top-ports 20 192.168.10.121Each port can be in one of the following states:
open- A service on the target accepted the connection or probe.closed- The host responded, but nothing is listening on that port.filtered- A firewall, packet filter, or network rule prevented Nmap from confirming the port state.unfiltered- The port is reachable, but Nmap cannot tell whether it is open or closed. You will see this state only with the ACK scan (-sA).open|filtered- Nmap received no reply, so the port is either open or filtered. This is the most common result for UDP ports.
To hide closed and filtered ports, add --open. Nmap also shows open|filtered and unfiltered ports, so the result is not limited to confirmed open ports:
nmap --open 192.168.10.121Ports and port ranges are specified with -p.
To scan only port 443, run:
nmap -p 443 192.168.10.121To scan multiple ports, separate them with commas:
nmap -p 80,443 192.168.10.121Use a dash for ranges. This example scans UDP ports 1 through 1024:
sudo nmap -sU -p 1-1024 192.168.10.121You can combine ranges and individual ports:
nmap -p 1-1024,8080,9000 192.168.10.121You can also use service names. For example, this scans the SSH port:
nmap -p ssh 192.168.10.121Discover Live Hosts with -sn
To perform host discovery without a port scan, use -sn:
sudo nmap -sn 192.168.10.0/24This tells Nmap to find which hosts are up and skip the port scan stage. It is useful when you want a fast inventory of live systems on a subnet before deciding what to scan next.
When you run it with sudo on a local Ethernet network, Nmap uses ARP requests to find hosts. ARP replies are hard to block on the same network, so this is the most reliable way to list devices on your LAN. As a regular user, Nmap tries TCP connections to ports 80 and 443. A closed port can still reveal a live host through a connection refusal, but Nmap can miss a host if probes to both ports are silently filtered.
In older Nmap releases, -sn was called -sP. You will still find nmap -sP in many guides, and current versions accept it, but -sn is the option to use.
Skip Host Discovery with -Pn
By default, Nmap performs host discovery first and scans only hosts it believes are online. That behavior is efficient, but it can miss hosts when firewalls drop discovery probes.
Use -Pn to skip host discovery and treat every target as online:
sudo nmap -Pn 192.168.10.121This is especially useful when a host blocks ping or other discovery probes but still has open ports you want to test. The tradeoff is speed: -Pn can make large scans much slower because Nmap attempts the requested scan against every target you specify.
If you see guidance online for -P0 or -PN, that refers to older Nmap syntax. The current option is -Pn.
Disable DNS Name Resolution
Nmap’s default behavior is to perform reverse-DNS resolution for each discovered host, which increases the scan time.
When scanning large ranges, disabling DNS lookups can make the scan noticeably faster. Use -n:
sudo nmap -n 192.168.10.0/24Control Scan Timing
Nmap uses timing templates to decide how fast it sends probes and how long it waits for replies. Set a template with -T followed by a number from 0 to 5:
-T0and-T1(paranoid, sneaky) - Very slow scans meant to avoid intrusion detection systems.-T2(polite) - Slows down the scan to use less bandwidth and fewer target resources.-T3(normal) - The default.-T4(aggressive) - Faster scan for reliable, modern networks.-T5(insane) - The fastest template, which may sacrifice accuracy.
On a local network or a decent broadband connection, -T4 is a good default. The Nmap documentation itself recommends it:
sudo nmap -T4 192.168.10.0/24If a scan starts reporting ports as filtered that you know are open, drop back to -T3. Slow or busy links can lose probes when Nmap sends them too quickly.
Detect Services, Versions, and OS Details
To identify the service and version behind an open port, use -sV:
sudo nmap -sV scanme.nmap.orgThis helps when the port number alone is not enough, especially if a service is running on a non-standard port.
...
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.7 ((Ubuntu))
135/tcp filtered msrpc
139/tcp filtered netbios-ssn
445/tcp filtered microsoft-ds
9090/tcp open zeus-admin?
9929/tcp open nping-echo Nping echo
...
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelThe VERSION column now shows the software behind each open port, such as OpenSSH on port 22 and Apache on port 80. A question mark after the service name, as in zeus-admin?, means Nmap could not identify the service through its probes and fell back to the port’s registered name. If a service responds but Nmap cannot identify it, Nmap prints a fingerprint and a submission URL.
To attempt operating system detection, use -O:
sudo nmap -O scanme.nmap.orgIf Nmap can fingerprint the remote system, the output looks similar to this:
...
Device type: general purpose
Running: Linux 5.X
OS CPE: cpe:/o:linux:linux_kernel:5
OS details: Linux 5.0 - 5.4
Network Distance: 18 hops
OS detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.47 secondsOS detection works best when Nmap finds at least one open and one closed TCP port. When the results are uncertain, Nmap prints its best guesses with a percentage next to each one.
If you want OS detection, version detection, default scripts, and traceroute
in one command, use -A:
sudo nmap -A 192.168.10.121Aggressive scan mode is useful during focused testing, but it is heavier and slower than a basic scan. It is usually better to start small and add options as needed.
Save nmap Output
By default, Nmap prints the information to standard output (stdout).
If you scan a large network or need to keep the results, save the output to a file.
To save the normal human-readable output, use -oN:
sudo nmap -sU -p 1-1024 192.168.10.121 -oN output.txtTo save XML output for later parsing or import into other tools, use -oX:
sudo nmap -sU -p 1-1024 192.168.10.121 -oX output.xmlIf you want normal, XML, and grepable output files in one run, use -oA with a base filename:
sudo nmap -sV 192.168.10.121 -oA scan-resultsThis creates three files: scan-results.nmap, scan-results.xml, and scan-results.gnmap.
Nmap still supports grepable output with -oG, which can be processed with tools such as grep
, awk
, and cut
. However, the Nmap documentation treats grepable output as deprecated, so XML is the better choice for new automation.
Use the Nmap Scripting Engine
One of the most powerful features of Nmap is its scripting engine. Nmap ships with hundreds of scripts , and you can also write your own scripts in the Lua language.
You can use scripts to gather extra information, test specific services, and automate common checks.
The easiest way to start is with -sC, which runs the default set of scripts. This is the same as --script default. Nmap selects default scripts for speed and usefulness, but includes a few it marks as intrusive, so use -sC only on hosts you have permission to test:
sudo nmap -sC -sV scanme.nmap.orgTo run a single script, pass its name to --script. The http-title script prints the title of the default page on a web server:
nmap -p 80 --script http-title scanme.nmap.orgThe script output appears under the port it ran against:
PORT STATE SERVICE
80/tcp open http
|_http-title: Go ahead and ScanMe!To see what a script does before you run it, use --script-help:
nmap --script-help http-titleThe help output includes the script categories. Scripts in the safe category are designed to avoid crashing services, using substantial resources, or exploiting vulnerabilities, but Nmap does not guarantee that they cannot cause problems. Scripts in the intrusive category carry a higher risk of disrupting a target, while vuln scripts check for known vulnerabilities and vary in behavior. Review a script before running it against production systems.
Quick Reference
For a printable quick reference, see the nmap cheatsheet .
| Task | Command |
|---|---|
| Basic scan | nmap target |
| SYN scan as root | sudo nmap -sS target |
| Scan specific ports | nmap -p 22,80,443 target |
| Scan all ports | nmap -p- target |
| Scan the 100 most common ports | nmap -F target |
| Hide closed and filtered ports | nmap --open target |
| Faster timing | sudo nmap -T4 target |
| Host discovery only | sudo nmap -sn 192.168.10.0/24 |
| Skip host discovery | sudo nmap -Pn target |
| Detect service versions | sudo nmap -sV target |
| OS detection | sudo nmap -O target |
| Default scripts | sudo nmap -sC target |
| Save normal output | nmap target -oN output.txt |
| Save all major formats | nmap target -oA scan-results |
Troubleshooting
Host appears down, but you know it is online
Try -Pn to skip host discovery. Some firewalls drop the probes Nmap uses to decide whether a host is up.
UDP scan is taking too long
Limit the ports with -p instead of scanning large UDP ranges. UDP scans are slower and often return less clear feedback than TCP scans.
DNS lookups are slowing the scan
Add -n to skip reverse DNS resolution, especially when scanning large networks.
You are not seeing SYN scan behavior
Run the command with sudo or specify -sS. Without raw packet privileges, Nmap falls back to TCP connect scan.
Conclusion
The nmap command is one of the most useful Linux tools for host discovery, port scanning, and service detection. If you want a lighter tool for quick socket tests, see netcat
next.
Linuxize Weekly Newsletter
A quick weekly roundup of new tutorials, news, and tips.
About the authors

Dejan Panovski
Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.
View author page