> For the complete documentation index, see [llms.txt](https://cas-cyber.gitbook.io/cas-cybersecurity/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cas-cyber.gitbook.io/cas-cybersecurity/scanning-and-enumeration/scanning-with-nmap.md).

# Scanning with nmap

### scanning with nmap

I don't solve this box yet, I'll go further with nmap command line scanner

> nmap -v 10.10.10.28&#x20;

**-v** stands for verbose (that we see some output)

In that case nmap sends ping packets to the target host. We can verify that with tcpdump:

> sudo tcpdump -i tun0 -p icmp

![listening for icmp packets on tun0 while doing a nmap scan](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhVGGytTDVQp2KX8yLD%2F-MhXuVoH7OawKKkPQBPW%2Fnmap01.png?alt=media\&token=9560baa3-0d78-4c18-9912-301421e3e041)

> sudo nmap 10.10.10.28 -v -Pn -sV -O

![no icmp packets detected](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhVGGytTDVQp2KX8yLD%2F-MhYB9TasbdrvthaoCBf%2Fnmap02.png?alt=media\&token=287c569c-53f3-4879-8ac4-5ff380d7c5e3)

If we use the paramater **-Pn** nmap doesn't send ping packets. -**sV** stands for Version detection and **-O** for OS detection.

-**A** enables OS detection, version detection, script scan and traceroute

-**p** is for specific ports (example -p22,80,443)

**-T** can be used for timing options (4 is default, 5 is maximum) --> Can be used to evade firewall and IDS detection

**-sS** stand for stealth scan or syn scan

-**oA scan\_results** writes an output file

<div align="left"><img src="https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhVGGytTDVQp2KX8yLD%2F-MhYDe6UD0zdlgdQslz5%2Fnmap03.png?alt=media&amp;token=99f83352-4f53-4158-af67-06db82349bec" alt=""></div>

**-iL targets.txt** Input list of ip addresses to scan

-**F** scan top 100 ports (fastscan)

-**sU** -**p U:53** performs UDP scan on port 53

**-sC** or --**script** use a specific NSE script

> sudo nmap --script smb-enum-users.nse -p 445 10.10.10.27

NSE scripts are located in **/usr/share/nmap/scripts**

![some smb nse scripts](https://3977837039-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MfT0VPyK6X13Egd9pzy%2F-MhYX-pL_o-Mf6vHiTMj%2F-MhYghq1j-U8ti39x-3v%2Fnmap06.png?alt=media\&token=578acbef-fe9d-40ea-8b63-14f42742ddd3)

NSE Scripts extends the core functionality of nmap. You can find more informations about them inside the help of nmap or the NSE reference: <https://nmap.org/nsedoc/>
