Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The basic Nmap command for Linux is nmap <target>. Replace <target> with an IP address, hostname, range, or subnet you own or are authorized to assess. Start with the smallest scope that answers your question: discovering live hosts, checking selected ports, and identifying services are separate scan choices.

Before you run Nmap

Run Nmap only against systems and networks you own or have explicit permission to assess. A scan sends network probes; its impact depends on the targets, options, scripts, and network controls involved. Confirm the permitted scope before scanning a shared, production, or third-party network.

Nmap normally performs host discovery and then scans ports on hosts it considers online. Discovery and port scanning are distinct: choose whether to find responsive hosts first or to skip that step, then choose the port and detection options that fit your task.

Start with a basic scan

A simple scan checks Nmap’s default set of common TCP ports on the target:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nmap 192.168.1.10

Use a hostname instead of an IP address if that is how the authorized target is identified. A default scan is a useful first look, not a complete inventory of every port or service.

Choose the targets and scope

You can provide one target, several targets, an address range, or a CIDR subnet. Use the narrowest form that covers the systems you intend to assess.

# Two individual targets
nmap 192.168.1.10 10.0.0.5

# Addresses from 192.168.1.1 through 192.168.1.50
nmap 192.168.1.1-50

# The 192.168.1.0/24 subnet
nmap 192.168.1.0/24

For a larger, pre-approved target list, store one target per line in a file. You can exclude a host that must not be scanned:

nmap -iL targets.txt --exclude 192.168.1.1

Discover hosts without scanning ports

Use -sn when you want host discovery only, without a port scan. For example, this checks which hosts Nmap can discover on the specified subnet:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo nmap -sn 192.168.1.0/24

Nmap’s discovery methods can include TCP SYN or ACK, UDP, SCTP, and ICMP probes. Which probes are useful depends on the network and your privileges; a host that does not respond to the probes may still be present.

Skip host discovery when probes are blocked

If discovery probes are blocked or filtered, Nmap may classify an up host as down and skip its port scan. Use -Pn to disable host discovery and treat the specified targets as online:

nmap -Pn 192.168.1.10

This does not make a target reachable or bypass a firewall. It tells Nmap to attempt the requested scan without first deciding whether the host is online. On a subnet, that can mean attempting scans against every specified address, so keep the target scope deliberate.

Limit which ports Nmap checks

Use -p to choose an explicit port list or range. Add --open if you want the report to show only ports Nmap identifies as open:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
# Check selected ports and show open results
nmap -p 22,80,443 --open 192.168.1.10

# Check ports 1 through 1024
nmap -p 1-1024 192.168.1.10

Restricting ports makes the scope clearer, but results describe only the ports and probes actually checked. A port omitted from the command has not been assessed by that scan.

Identify services and estimate the operating system

Service and version detection

Add -sV to probe open ports for service and application version information:

nmap -sV 192.168.1.10

Version detection can provide more detail than a port-state result alone. The result is based on responses to probes, so it should be treated as an identification result rather than proof of a specific software build.

OS fingerprinting

Use -O to request operating-system fingerprinting. Extra verbosity can show more scan detail:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo nmap -O -v 192.168.1.10

OS detection is an estimate based on network responses. Nmap can return multiple possible matches or indicate that it is “just guessing,” so do not treat the fingerprint as definitive identification.

Combined advanced scan

The -A option bundles OS detection, version detection, default scripts, and traceroute. The manual’s representative example also uses timing option -T4:

nmap -A -T4 192.168.1.10

This is not the universal default scan. Its extra detection and script activity can be more intrusive than a basic scan; use it only when those checks are appropriate and authorized.

Use Nmap scripts selectively

Nmap Scripting Engine (NSE) scripts can gather additional information or perform other checks, and behavior varies by script and category. Use a named script when you know what it does and have authorization for that activity:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nmap --script <script-name> 192.168.1.10

The -sC option runs the default script set:

nmap -sC 192.168.1.10

Scripts can use information Nmap has collected about hosts, ports, services, and OS matches. Do not assume that every script is passive or suitable for every target.

Interpret port states as observations

A port state describes what Nmap could determine from its probes and the network’s responses; it is not a guarantee about the target’s underlying configuration.

  • Open: Nmap received a response consistent with an application accepting connections on that port.
  • Closed: Nmap received a response indicating no application is accepting connections on the port.
  • Filtered: A filter or network obstacle prevented Nmap from determining whether the port is open or closed.
  • Open|filtered: Nmap could not distinguish an open port from one whose probes were filtered.
  • Closed|filtered: Nmap could not distinguish a closed port from one whose probes were filtered.

These combined states represent ambiguity, not a third underlying port condition. Probe type, filtering, and probe limits can affect what Nmap is able to report.

See why Nmap chose a state

Add --reason to include the reason Nmap assigned a result, and use -v or -vv for more progress and scan detail:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
nmap --reason -vv 192.168.1.10

Verbose output can include progress, version and script activity, and scan completion details. It adds context to the run; it does not remove uncertainty caused by filtering or limited probes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Save scan results for review or tools

Choose the output format based on how the results will be used:

Option Output Best suited to
-oN Normal text Human review and readable reports
-oX XML Structured tooling and data processing
-oG Grepable text Simple text processing
-oA A set of common formats Keeping several output forms from one run

Examples:

nmap -oN report.txt 192.168.1.10
nmap -oX report.xml 192.168.1.10
nmap -oG report.gnmap 192.168.1.10
nmap -oA audit-2026-09-28 192.168.1.10

The final command writes the common output set using audit-2026-09-28 as the filename base. Store scan output in an approved location and handle it according to your organization’s rules; it can reveal details about systems and services.

Which command should you use?

Goal Command pattern What it does
Check common ports on one host nmap <target> Runs a default scan of common TCP ports
Find discoverable hosts on a subnet nmap -sn <authorized-subnet> Performs host discovery without a port scan
Scan despite blocked discovery probes nmap -Pn <authorized-target> Skips discovery and treats targets as online
Check selected ports nmap -p <ports> <target> Limits the port scope
Identify services and versions nmap -sV <target> Adds service and version detection
Estimate the operating system nmap -O <target> Requests OS fingerprinting
Collect bundled advanced details nmap -A <target> Combines OS detection, version detection, default scripts, and traceroute
Keep a readable report nmap -oN <file> <target> Writes normal text output

For an extended treatment of scanning concepts, performance considerations, and scripting, see the Nmap Network Scanning official guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.