Introduction
You can't secure what you don't know exists. Rogue IoT devices, forgotten test servers, an accidentally-exposed RDP port, a switch someone plugged in last year and never documented — most SMB networks have more attack surface than anyone on the IT team could list from memory. Nmap ("Network Mapper") has been the standard tool for finding it since 1997, and it's still the fastest way to answer "what's actually running on this network right now."
This guide covers building an accurate asset inventory with Nmap, identifying service versions and stale software, and using the Nmap Scripting Engine (NSE) to flag common misconfigurations — all without needing a full vulnerability scanner like OpenVAS for a first pass.
In this guide you will:
- Install Nmap and understand the difference between host discovery, port scanning, and service/OS detection
- Run a safe, fast discovery sweep across a subnet
- Identify service versions and flag outdated software
- Use NSE scripts for vulnerability and misconfiguration checks
- Export results and schedule recurring inventory scans
- Avoid the mistakes that get scans flagged as an attack
Prerequisites
- A Linux (Ubuntu/Debian shown), macOS, or Windows host on the target network
sudo/admin rights — SYN scans and OS detection require raw socket access- Written authorization: only scan networks and hosts you own or have explicit permission to test. Unauthorized port scanning can violate computer-misuse laws in your jurisdiction and most acceptable-use policies. On a corporate or client network, get sign-off in writing before you scan.
- A rough idea of your network's CIDR ranges (check your router/DHCP scope, e.g.
192.168.1.0/24)
Step 1: Install Nmap
Ubuntu/Debian:
sudo apt update
sudo apt install -y nmapmacOS (Homebrew):
brew install nmapWindows:
Download the installer from nmap.org — it bundles Npcap for raw packet capture. Accept the Npcap driver install when prompted.
Verify the install and check the version:
nmap --versionStep 2: Discover live hosts on the network
Before scanning ports, find out what's actually up. A ping sweep (-sn, "scan no port") sends ICMP echo, TCP SYN to 443, and ARP requests on local subnets — fast and low-noise:
sudo nmap -sn 192.168.1.0/24Output lists each responding host with its IP and, on the local segment, its MAC address and vendor (handy for spotting an unfamiliar device — "Espressif" showing up on a server VLAN is worth a second look). Save this as your discovery baseline:
sudo nmap -sn 192.168.1.0/24 -oG - | awk '/Up$/{print $2}' > live-hosts.txtStep 3: Scan for open ports
With a host list in hand, scan the top ports for speed, or all 65535 for a thorough audit.
Fast scan (top 1000 ports, SYN stealth scan):
sudo nmap -sS -T4 -iL live-hosts.txt -oN scan-top1000.txt-sS— TCP SYN scan (half-open, doesn't complete the handshake — faster and quieter than a full connect scan)-T4— aggressive timing template (safe on LANs; drop to-T2on fragile WAN links or IoT gear that chokes under load)-iL— read targets from a file
Full port range (slower, use for a periodic deep audit, not daily runs):
sudo nmap -sS -p- -T4 -iL live-hosts.txt -oN scan-all-ports.txtStep 4: Identify service versions and OS
Open ports alone don't tell you much — you need to know what's listening. Add -sV for version detection and -O for OS fingerprinting:
sudo nmap -sS -sV -O -p 22,80,443,445,3389,8080 192.168.1.0/24 -oN scan-services.txt-sV probes each open port and reports the actual software and version banner where it can, e.g.:
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11
443/tcp open https nginx 1.18.0
3389/tcp open ms-wbt-server Microsoft Terminal Services
Cross-reference version strings against your patch inventory. OpenSSH 8.2p1 on a host that should be running 9.x is a signal someone missed a patching cycle — flag it before it shows up in a Trivy or OpenVAS scan as a formal finding.
For an even faster combined sweep, -A bundles version detection, OS detection, script scanning, and traceroute:
sudo nmap -A -T4 192.168.1.60Use -A against a single host you're investigating, not a whole subnet — it's noisy and slow at scale.
Step 5: Run NSE scripts for misconfigurations
The Nmap Scripting Engine ships hundreds of scripts for vulnerability checks, default-credential testing, and protocol-specific enumeration. The vuln category is a good general-purpose sweep:
sudo nmap -sV --script vuln 192.168.1.50Useful targeted scripts:
# Check for SMB signing disabled / SMBv1 (both common ransomware pivot points)
sudo nmap --script smb-security-mode,smb-protocols -p 445 192.168.1.50
# Check TLS/SSL cipher strength and certificate expiry
sudo nmap --script ssl-enum-ciphers,ssl-cert -p 443 192.168.1.50
# Check for anonymous FTP / open shares
sudo nmap --script ftp-anon -p 21 192.168.1.50List every installed script and category with nmap --script-help all | less, or browse categories at /usr/share/nmap/scripts/ (Linux) — auth, default, discovery, intrusive, safe, vuln are the ones you'll use most. Stick to safe and vuln categories on production systems; intrusive scripts can crash fragile services (old printers and embedded management interfaces are notorious).
Step 6: Export results for tracking
Nmap supports three output formats simultaneously with -oA <basename>:
sudo nmap -sS -sV -iL live-hosts.txt -oA weekly-audit-2026-09-28This writes .nmap (human-readable), .gnmap (grep-able), and .xml. The XML output is the one worth keeping — pipe it into a diffing tool to catch new/changed hosts between scans:
# Convert to HTML for a shareable report
xsltproc weekly-audit-2026-09-28.xml -o weekly-audit-2026-09-28.htmlFor recurring inventory, diff this week's XML against last week's with a script, or feed both into a simple Python set comparison on host/port tuples — a new open port on an existing host is exactly the kind of drift you want flagged, not discovered during an incident.
Verification / Testing
Confirm your scan actually captured what you expect:
# Count discovered hosts
grep -c "Up$" live-hosts.txt
# Confirm a known-open port shows up (e.g. your web server)
grep "80/tcp" scan-services.txt
# Sanity-check against a host you know the answer for
sudo nmap -sV -p 22 <a-host-you-know-runs-ssh>If a host you know is up doesn't appear in the ping sweep, it may be dropping ICMP — rerun with -Pn (skip host discovery, treat all targets as up) to scan it directly:
sudo nmap -Pn -sS -p- 192.168.1.75Troubleshooting
Scan returns "all ports filtered" or nothing at all
A host-based firewall (Windows Defender Firewall, ufw, a NAC appliance) may be dropping unsolicited packets. Try -Pn to skip the discovery ping, and confirm from the scanning host that basic connectivity works (ping, telnet <ip> <port>).
SYN scan (-sS) fails with a permissions error
Raw socket access needs root/admin. On Linux, run with sudo or grant the capability directly: sudo setcap cap_net_raw+eip $(which nmap). On Windows, run your terminal as Administrator.
Scan takes forever on a large subnet
Drop from -p- (all 65535 ports) to -F (top 100 ports) for routine sweeps, and reserve full-range scans for a scheduled weekly/monthly job. --min-rate 1000 can also speed things up on networks with low latency, but test it on a non-production segment first — aggressive rates can trip IDS/IPS or overwhelm low-power devices.
Results look different than last week for no reason DHCP lease churn is the most common cause — an IP that was a printer last week might be a laptop today. Track by MAC address alongside IP when building a persistent asset inventory, and cross-reference against your DHCP server's lease table.
A scan gets flagged by your own IDS/EDR That's the system working as intended. Add the scanning host to an allowlist in Suricata/CrowdSec/your EDR console before running scheduled audits, or coordinate scan windows with whoever monitors those alerts so a false positive doesn't turn into a 2am page.
Summary
Nmap turns "I think that's everything on the network" into an actual, verifiable list — live hosts, open ports, service versions, and a first pass at misconfigurations, all from a single tool. Run a ping sweep to build your host inventory, follow up with version detection to catch stale software, layer in NSE vuln/safe scripts for known misconfigurations, and export XML so you can diff week over week. It won't replace a dedicated vulnerability scanner like OpenVAS for CVE-level depth, but as a fast, recurring "what's actually out there" check, nothing beats it — and it's the first tool worth running before you can secure anything else.