penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration testing is one of the most interesting areas of cybersecurity.

It combines networking, Linux, Windows, programming, web technologies, vulnerability analysis, security testing and technical reporting.

But there is one major problem for beginners:

What should I learn first, and what should I learn next?

Many beginners start with Kali Linux, install several security tools and immediately jump into advanced tutorials.

That approach can create the illusion of progress without building the underlying knowledge needed to understand what the tools are actually doing.

A better approach is to build your skills in layers:

Computer Fundamentals
        ↓
Networking
        ↓
Linux + Windows
        ↓
Programming
        ↓
Web Technologies
        ↓
Security Fundamentals
        ↓
Nmap + Traffic Analysis
        ↓
Web Security
        ↓
Hands-on Labs
        ↓
Penetration Testing Methodology
        ↓
Specialization
        ↓
Reporting
        ↓
Portfolio

This guide explains that roadmap in detail.

Important: Penetration testing must be authorized. Practice only on systems you own, deliberately vulnerable labs, training environments, bug-bounty targets explicitly within scope, or systems covered by written permission.

What Is Penetration Testing?

Penetration testing, often called pentesting, is a structured form of security testing in which authorized testers evaluate whether weaknesses in a system can be used to compromise security under defined constraints.

NIST defines penetration testing as a methodology where assessors attempt to circumvent or defeat security features under specified constraints. NIST SP 800-115 also provides guidance for planning, conducting and evaluating technical security tests. (NIST Penetration Testing)

A simplified process is:

Authorization
      ↓
Scope
      ↓
Discovery
      ↓
Enumeration
      ↓
Vulnerability Analysis
      ↓
Controlled Validation
      ↓
Reporting
      ↓
Remediation
      ↓
Retesting

What Does a Penetration Tester Do?

A penetration tester may be responsible for:

  • Understanding the authorized scope
  • Discovering systems and services
  • Analyzing applications
  • Identifying vulnerabilities
  • Validating selected findings
  • Assessing potential impact
  • Documenting evidence
  • Writing security reports
  • Providing remediation guidance
  • Performing retesting after fixes

The exact responsibilities vary by organization and specialization.


Penetration Testing Roadmap at a Glance

Stage Main Focus
1Computer fundamentals
2Networking
3Linux
4Windows
5Programming and scripting
6Web technologies
7Cybersecurity fundamentals
8Security tools
9Hands-on labs
10Testing methodology
11Specialization
12Reporting and portfolio

Stage 1: Learn Computer Fundamentals

Before learning penetration testing, understand how computers actually work.

Learn:

  • CPU
  • RAM
  • Storage
  • Operating systems
  • Processes
  • Files and directories
  • Users and permissions
  • Applications
  • Client-server architecture

Questions to Understand

  • What is a process?
  • What is a service?
  • How does an application communicate with another system?
  • What is a user account?
  • What are file permissions?
  • What happens when a program starts?

You do not need to become a hardware engineer.

The goal is to understand the basic environment in which security problems occur.


Stage 2: Master Networking

Networking is one of the most important foundations for penetration testing.

Learn these concepts:

  • IPv4
  • IPv6 basics
  • MAC addresses
  • TCP
  • UDP
  • Ports
  • DNS
  • DHCP
  • HTTP
  • HTTPS
  • Routing
  • NAT
  • Firewalls
  • VPNs
  • Subnetting

You should eventually be comfortable explaining:

User
 ↓
DNS
 ↓
IP Address
 ↓
Router
 ↓
TCP Connection
 ↓
Port
 ↓
Service
 ↓
Application

Without this knowledge, tools such as Nmap can become little more than a collection of commands.


Stage 3: Learn Linux

Linux is an important operating system for security learners.

Learn:

  • Filesystem structure
  • File permissions
  • Users and groups
  • Processes
  • Services
  • Networking
  • Logs
  • SSH
  • Shell scripting

Essential Linux Commands

pwd
ls
cd
mkdir
cp
mv
rm
cat
less
grep
find
chmod
chown
ps
top
ip
ss
curl
ssh
journalctl

Learning these commands will make later security tooling much easier.


Stage 4: Learn Windows

Penetration testing is not limited to Linux systems.

Many enterprise environments use Windows extensively.

Learn:

  • Windows users and groups
  • NTFS permissions
  • Processes
  • Services
  • PowerShell
  • Event Viewer
  • Windows Defender
  • Registry basics
  • Authentication
  • Active Directory fundamentals

Understanding Windows becomes especially important if you want to explore enterprise penetration testing.


Stage 5: Learn Programming and Scripting

You do not need to become an expert programmer before starting penetration testing.

However, scripting becomes extremely useful as your skills grow.

Technology Why Learn It?
PythonAutomation, APIs, scripts and data processing
BashLinux automation
PowerShellWindows administration and automation
SQLDatabase and application security
JavaScriptWeb application understanding

For most beginners, Python + Bash + SQL + basic JavaScript is a useful combination.


Stage 6: Learn Web Technologies

If you want to test websites or APIs, you must first understand how they work.

Learn:

  • HTML
  • CSS basics
  • JavaScript basics
  • HTTP requests
  • HTTP responses
  • Headers
  • Cookies
  • Sessions
  • Authentication
  • Authorization
  • REST APIs
  • JSON
  • Databases

A simplified web architecture looks like:

Browser
   ↓
Frontend
   ↓
API / HTTP
   ↓
Backend
   ↓
Database

Security testing becomes much easier when you understand each layer.


Stage 7: Learn Cybersecurity Fundamentals

Before studying specific vulnerabilities, understand the basic language of security.

Learn:

  • Confidentiality
  • Integrity
  • Availability
  • Authentication
  • Authorization
  • Accounting and logging
  • Least privilege
  • Defense in depth
  • Threats
  • Vulnerabilities
  • Risk

Understand the CIA Triad

Confidentiality
       /\
      /  \
     /    \
    /      \
Integrity--Availability

These concepts provide the foundation for understanding why security weaknesses matter.


Stage 8: Learn Authentication and Authorization

This is particularly important for web and API security.

Authentication: Who are you?

Authorization: What are you allowed to do?

Study:

  • Passwords
  • MFA
  • Sessions
  • Cookies
  • Tokens
  • Roles
  • Permissions
  • Access-control models

Many serious application-security problems involve incorrect authorization rather than simply weak passwords.


Stage 9: Learn Cryptography Basics

You do not need advanced mathematics to begin.

Understand:

  • Encryption
  • Decryption
  • Symmetric cryptography
  • Asymmetric cryptography
  • Hashing
  • Digital signatures
  • Certificates
  • Public/private keys
  • TLS basics

You should be able to explain why passwords should be protected using appropriate password-hashing mechanisms rather than simple reversible encryption.


Stage 10: Learn Vulnerabilities

Now start studying common vulnerability classes.

Important areas include:

  • Broken access control
  • Injection
  • Authentication failures
  • Security misconfiguration
  • Cryptographic failures
  • Insecure design
  • Outdated components
  • Session-management weaknesses
  • Server-side request issues

For web security, OWASP's Web Security Testing Guide provides a structured reference for application testing. OWASP currently lists version 4.2 as the latest released WSTG version while version 5.0 is under development. (OWASP WSTG)


Stage 11: Learn Nmap

Nmap is commonly used for network discovery and service identification.

Start with your local lab:

nmap 127.0.0.1

Then learn:

nmap -p 22,80,443 127.0.0.1

nmap -sV 127.0.0.1

nmap -p- 127.0.0.1

nmap -oA lab-scan 127.0.0.1

Learn what the results mean before adding more advanced options.


Stage 12: Learn Wireshark

Wireshark helps you inspect network traffic.

Learn:

  • Packets
  • Frames
  • TCP handshakes
  • UDP traffic
  • DNS requests
  • HTTP traffic
  • TLS concepts
  • Source and destination addresses
  • Ports

Try capturing traffic generated by your own applications and understand what each packet represents.

Packet analysis is an excellent way to strengthen networking knowledge.


Stage 13: Learn Burp Suite

Burp Suite is widely used for web application security testing.

Start with:

  • Proxy
  • HTTP request/response inspection
  • Repeating requests
  • Modifying requests in a lab
  • Understanding cookies
  • Understanding authentication flows

Do not begin by trying to memorize every feature.

First understand:

Browser
   ↓
Burp Proxy
   ↓
Web Application
   ↓
Response
   ↓
Burp
   ↓
Browser

Once that flow is clear, the rest of the tool becomes easier to learn.


Stage 14: Study OWASP Web Security Testing

If web application security is your target, OWASP is one of the most useful learning resources available.

The current OWASP WSTG covers areas including:

  • Information gathering
  • Configuration testing
  • Identity management
  • Authentication testing
  • Authorization testing
  • Session management
  • Input validation
  • Error handling
  • Cryptography
  • Business logic

OWASP describes WSTG as a flexible methodology and technique reference rather than a rigid checklist. Its latest released version is currently 4.2, with 5.0 under development. (OWASP WSTG Introduction)


Stage 15: Learn Enumeration

Enumeration means gathering detailed information about identified systems and services.

Depending on the authorized target, you may study:

  • Service versions
  • Application technologies
  • Authentication mechanisms
  • Available endpoints
  • Network relationships
  • Security controls

The key is understanding what information is useful and why.


Stage 16: Learn Vulnerability Analysis

Once you understand a system, identify potential weaknesses.

Possible sources include:

  • Manual analysis
  • Automated scanners
  • Configuration reviews
  • Application behavior
  • Source-code review, when available
  • Known vulnerability information

Do not automatically treat scanner output as proof.

Always analyze the finding in context.


Stage 17: Learn Controlled Validation

A suspected vulnerability may need to be validated.

Validation should occur only when:

  • The target is in scope
  • The action is permitted
  • The potential impact is understood
  • The test is controlled
  • Sensitive data is protected

The purpose is to establish whether a suspected weakness actually produces the reported security impact.


Stage 18: Learn Penetration Testing Methodology

Tools are not a methodology.

One recognized reference described by OWASP is the Penetration Testing Execution Standard (PTES), which organizes penetration testing into seven phases:

  1. Pre-engagement Interactions
  2. Intelligence Gathering
  3. Threat Modeling
  4. Vulnerability Analysis
  5. Exploitation
  6. Post Exploitation
  7. Reporting

OWASP's methodology overview also references NIST SP 800-115, PCI penetration-testing guidance and other testing methodologies. (OWASP Penetration Testing Methodologies)

These phases should be adapted to the engagement rather than treated as a universal script.


Stage 19: Learn Pre-Engagement

This phase establishes the rules of the assessment.

Understand:

  • Scope
  • Objectives
  • Testing dates
  • Authorized systems
  • Excluded systems
  • Permitted methods
  • Prohibited methods
  • Emergency contacts
  • Reporting requirements

A professional penetration tester should be comfortable reading and following a scope document.


Stage 20: Learn Intelligence Gathering

Before deeper testing, understand the target.

This can include:

  • Domains
  • Subdomains
  • IP addresses
  • Technologies
  • Applications
  • Publicly available information

Always keep information gathering within the authorized scope.


Stage 21: Learn Threat Modeling

Threat modeling asks questions such as:

  • What are the important assets?
  • Who might attack them?
  • What attack paths could exist?
  • What security controls are present?
  • What happens if a control fails?

Threat modeling gives penetration testing context.


Stage 22: Learn Post-Exploitation Concepts

At an advanced level, security testers may need to understand what could happen after an initial compromise.

Study concepts such as:

  • Privilege boundaries
  • Credential exposure
  • Network segmentation
  • Lateral movement concepts
  • Persistence concepts
  • Detection opportunities

Practice these concepts only inside explicitly authorized labs.

The goal is to understand potential business impact and defensive controls, not to gain access to unrelated systems.


Stage 23: Learn Reporting

Reporting is one of the most important professional skills.

A good report may contain:

Executive Summary
Scope
Methodology
Limitations
Findings
Evidence
Risk
Impact
Recommendations
Retest Results
Appendices

A technical person should be able to reproduce the issue from the information provided, while management should be able to understand the business significance.


What Should a Penetration Testing Finding Contain?

A practical finding structure is:

Title
↓
Affected Asset
↓
Description
↓
Evidence
↓
Impact
↓
Risk Context
↓
Recommendation
↓
References
↓
Retest Status

For example:

Finding:
Insufficient Authorization

Affected Asset:
Authorized Test Application

Description:
A tested user role was able to access a resource
outside its intended permission boundary.

Impact:
The issue may expose information intended for
another role.

Recommendation:
Enforce server-side authorization checks for
every protected resource and action.

Retest:
Verify that the restricted request is denied.

Stage 24: Learn Vulnerability Prioritization

Not every vulnerability deserves the same remediation priority.

Consider:

  • Likelihood
  • Technical severity
  • Asset importance
  • Exposure
  • Exploitability
  • Business impact
  • Existing controls

This helps organizations decide where to spend limited remediation resources.


Stage 25: Build a Home Pentesting Lab

A lab is one of the best ways to learn penetration testing safely.

A basic setup could contain:

Host Computer
       |
   Virtualization
       |
+------+----------------+
|                       |
Tester VM            Target VM
|                       |
|                Vulnerable App
|                       |
+-----------+-----------+
            |
       Isolated Lab

You can install Linux and Windows virtual machines and connect deliberately vulnerable applications to a controlled network.


How Much Hardware Do You Need?

You do not need an expensive server to begin.

A basic computer that can run one or more virtual machines can be enough for many beginner exercises.

As you progress, more RAM and storage can make virtualization easier.

For resource-constrained learners, start small:

  • One Linux VM
  • One target VM
  • One isolated network

You can expand the lab later.


Stage 26: Build Projects

Projects turn knowledge into evidence.

Beginner Projects

  • Local network inventory tool
  • Python log analyzer
  • File integrity monitor
  • Security headers checker
  • Hashing demonstration application
  • Linux security checklist

Intermediate Projects

  • Mini vulnerability-management dashboard
  • Web security testing report
  • Security log monitoring system
  • Network monitoring dashboard
  • Authentication monitoring tool
  • Cloud configuration checker

Stage 27: Build Your Portfolio

A strong penetration-testing portfolio can include:

  • GitHub projects
  • Lab documentation
  • Security reports
  • Web-security write-ups
  • CTF write-ups from permitted environments
  • Python security scripts
  • Network-analysis projects
  • Remediation examples

For each project, use a consistent structure:

Problem
Scope
Environment
Approach
Tools
Findings
Impact
Remediation
Retest
Lessons Learned

Stage 28: Choose a Specialization

Penetration testing is broad.

Eventually, choose an area to explore deeply.

Web Application Security

Focus on applications, APIs, authentication, authorization, sessions and business logic.

Network Penetration Testing

Focus on network services, segmentation, protocols and infrastructure.

Active Directory

Focus on Windows enterprise environments, identity and access relationships.

Cloud Security

Focus on cloud identities, permissions, configurations and exposed resources.

Mobile Security

Focus on mobile applications and backend communication.

Red Teaming

Focus on broader adversary simulation within carefully defined rules of engagement.


Web Pentesting Roadmap

HTTP
 ↓
HTML / JavaScript
 ↓
Cookies / Sessions
 ↓
Authentication
 ↓
Authorization
 ↓
APIs
 ↓
SQL / Databases
 ↓
OWASP
 ↓
Burp Suite
 ↓
Web Security Labs
 ↓
Reporting

OWASP's Web Security Testing Guide is particularly useful for this path. The project currently lists WSTG 4.2 as its latest released version while 5.0 is being developed. (OWASP WSTG)


Network Pentesting Roadmap

Networking
 ↓
TCP / UDP
 ↓
Ports
 ↓
Services
 ↓
Nmap
 ↓
Wireshark
 ↓
Enumeration
 ↓
Firewall Concepts
 ↓
Network Security
 ↓
Controlled Validation
 ↓
Reporting

Active Directory Learning Roadmap

Windows Fundamentals
 ↓
Users & Groups
 ↓
Domains
 ↓
Active Directory
 ↓
Kerberos Concepts
 ↓
LDAP Concepts
 ↓
Group Policies
 ↓
Permissions
 ↓
Enterprise Security
 ↓
Authorized AD Lab
 ↓
Reporting

Do not begin with advanced Active Directory attack techniques before understanding Windows and identity fundamentals.


Cloud Pentesting Roadmap

Cloud Fundamentals
 ↓
IAM
 ↓
Networking
 ↓
Storage
 ↓
Compute
 ↓
Logging
 ↓
Secrets
 ↓
Configuration
 ↓
Cloud Security Testing
 ↓
Reporting

Cloud testing requires additional attention to the provider's security-testing policies and the organization's authorization.


Certifications and Penetration Testing

Certifications can provide structure and may help demonstrate certain knowledge or hands-on capabilities.

Before selecting one, compare:

  • Current syllabus
  • Exam format
  • Practical requirements
  • Prerequisites
  • Cost
  • Renewal requirements
  • Relationship to your target role

Do not choose a certification simply because somebody says it is "the best."

First identify the skills you need.


Skills vs Certifications

Skill Evidence Certification Evidence
ProjectsExam result
Lab reportsCredential
GitHub repositoriesCertification body
Practical demonstrationsStructured learning path
Security write-upsFormal assessment

For a strong profile, skills and documented practice should support any certifications you earn.


A 12-Month Penetration Testing Study Plan

Month Focus
1Computer fundamentals
2Networking fundamentals
3Linux
4Windows + PowerShell
5Python + SQL
6HTTP + Web Technologies
7Security fundamentals
8Nmap + Wireshark
9Web security + Burp Suite
10Hands-on labs
11Specialization + projects
12Reporting + portfolio + interview preparation

This is a flexible example. Your progress depends on your existing knowledge, available study time and amount of hands-on practice.


A Daily Penetration Testing Study Routine

A balanced routine could look like:

30 min → Theory
30 min → Networking / Linux
60 min → Hands-on Lab
30 min → Notes
30 min → Project

On busy days, even one focused practical session can be useful.


How to Practice Efficiently

Do not spend all your time watching tutorials.

Use a cycle such as:

Learn
 ↓
Practice
 ↓
Break
 ↓
Understand
 ↓
Fix
 ↓
Document
 ↓
Repeat

The "document" step is often ignored, but it becomes valuable when building a professional portfolio.


How to Take Notes

Create separate notes for:

  • Networking
  • Linux
  • Windows
  • Web security
  • Nmap
  • Wireshark
  • Burp Suite
  • OWASP
  • Labs
  • Reporting

For every new concept, write:

What is it?
Why does it matter?
How does it work?
How can I detect it?
How can it be fixed?

How to Measure Your Progress

Do not measure your progress only by the number of tools installed.

Instead, ask whether you can:

  • Explain how a network works
  • Interpret Nmap results
  • Read HTTP requests
  • Understand authentication
  • Identify an authorization problem in a lab
  • Analyze logs
  • Write a Python automation script
  • Explain the impact of a finding
  • Recommend a remediation
  • Write a professional report

Common Beginner Mistakes

1. Starting With Advanced Exploitation

Build fundamentals first.

2. Ignoring Networking

Network knowledge is foundational.

3. Learning Only Kali Linux

Kali is an environment, not a substitute for understanding Linux and security.

4. Memorizing Commands

Understand why and when to use a command.

5. Using Automated Scanners Without Verification

Scanner results can require manual validation.

6. Ignoring Reporting

Professional security work requires clear communication.

7. Practicing on Unauthorized Targets

This can create legal, contractual and operational problems.

8. Collecting Certifications Without Practical Work

Build real technical evidence alongside any certifications.


What Should You Avoid Learning First?

You do not need to begin with:

  • Advanced exploit development
  • Complex malware analysis
  • Advanced reverse engineering
  • Highly specialized hardware attacks
  • Complex red-team infrastructure

These topics can come later.

Build a strong foundation first.


How to Build a Professional Pentesting Mindset

Instead of asking:

"Which exploit should I run?"

learn to ask:

"What is the system supposed to do, what security control protects it, and can I demonstrate a weakness within the authorized scope?"

This mindset encourages analysis before action.


Penetration Testing and Secure Development

Application security should not depend only on penetration testing after an application has been built.

OWASP's current testing framework emphasizes considering security throughout the software lifecycle, including definition, design, development, deployment, maintenance and operations. (OWASP Testing Framework)

A broader secure-development process can look like:

Requirements
 ↓
Threat Modeling
 ↓
Secure Design
 ↓
Secure Coding
 ↓
Code Review
 ↓
Security Testing
 ↓
Deployment
 ↓
Monitoring
 ↓
Penetration Testing
 ↓
Improvement

Penetration testing is therefore one part of a larger security program.


How a Penetration Tester Should Think About a Finding

A useful mental model is:

Weakness
   ↓
Can It Be Validated?
   ↓
What Access Does It Provide?
   ↓
What Resource Is Affected?
   ↓
What Is The Security Impact?
   ↓
How Should It Be Fixed?

This turns technical observations into actionable security findings.


Penetration Testing Portfolio Checklist

  • □ Linux lab
  • □ Windows lab
  • □ Networking project
  • □ Nmap project
  • □ Wireshark analysis
  • □ Web-security lab
  • □ Burp Suite exercise
  • □ Python automation project
  • □ Vulnerability report
  • □ Remediation example
  • □ GitHub repository
  • □ Technical write-up

Frequently Asked Questions

1. What should I learn first for penetration testing?

Start with computer fundamentals, networking, Linux and Windows basics. Then add programming, web technologies and security fundamentals.

2. Is Kali Linux enough to become a penetration tester?

No. Kali Linux provides a useful security-testing environment, but it does not replace networking, Linux, Windows, programming, web-security knowledge and hands-on practice.

3. Is networking important for penetration testing?

Yes. Networking is one of the most important foundations for understanding ports, services, protocols, firewalls and network behavior.

4. Do I need programming for penetration testing?

You do not need advanced programming immediately, but Python, Bash, PowerShell, SQL and JavaScript can become very useful as your skills develop.

5. Which programming language should I learn first?

Python is a practical starting point because it is useful for automation, scripting, APIs and data processing.

6. Should I learn web security?

Yes, especially if you are interested in websites and APIs. HTTP, authentication, authorization, sessions, databases and application architecture are important foundations.

7. Is Nmap enough for penetration testing?

No. Nmap is useful for discovery and service identification, but a penetration test requires planning, analysis, validation, reporting and remediation.

8. What is the difference between vulnerability assessment and penetration testing?

Vulnerability assessment generally focuses on finding potential weaknesses, while penetration testing can include controlled validation of selected weaknesses and their security impact.

9. Can I practice penetration testing on public websites?

Do not assume that public availability means authorization. Use your own systems, training platforms, deliberately vulnerable labs or systems where you have explicit permission.

10. How long does it take to learn penetration testing?

There is no universal timeline. Progress depends on your current technical knowledge, study time, hands-on practice and chosen specialization.

11. Do I need certifications?

Certification requirements vary by role and employer. Certifications can be useful, but they should complement practical knowledge and project experience.

12. Is reporting really important?

Yes. A professional tester needs to communicate findings, impact and remediation clearly. Technical testing without useful documentation has limited value to the organization.

13. What is the PTES methodology?

The Penetration Testing Execution Standard organizes penetration testing into seven phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting. OWASP references PTES in its penetration-testing methodology guidance. (OWASP PTES Reference)

14. What is OWASP WSTG?

The OWASP Web Security Testing Guide is a practical reference for testing web applications and web services. The project currently lists version 4.2 as the latest released version while version 5.0 is under development. (OWASP WSTG)


Final Thoughts

Penetration testing is not something you learn by installing a security distribution and memorizing commands.

A stronger roadmap is:

Computers → Networking → Linux → Windows → Programming → Web → Security → Tools → Labs → Methodology → Reporting → Specialization

Build each layer before moving heavily into the next one.

NIST's technical security-testing guidance emphasizes planning, execution and evaluation, while OWASP's current testing resources emphasize adaptable methodologies, risk-based prioritization and a combination of automated and manual techniques. (NIST SP 800-115)

The biggest mistake beginners make is focusing on how to attack before understanding how the system works.

Reverse that order.

Learn the technology first, practice safely, document your findings, understand remediation and gradually specialize.

That gives you a much more useful foundation for a long-term penetration-testing career.

Remember: Authorization is part of the technical process, not an optional detail. Always know exactly what you are allowed to test before performing security testing.

Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

What Is Ethical Hacking? Complete Beginner Guide to Ethical Hacking

What Is Ethical Hacking? Complete Beginner Guide

When people hear the word hacking, they often imagine someone breaking into a computer illegally.

But hacking itself is not automatically malicious.

Ethical hacking refers to authorized security work in which a professional looks for weaknesses in systems, applications, networks or devices so those weaknesses can be understood and fixed.

The most important word is:

Authorization

Without authorization, attempting to access or test another person's system can become unauthorized activity.

With authorization, the same general security-testing techniques can be used as part of a legitimate security assessment.

This article explains ethical hacking from the ground up, including its meaning, methodology, skills, tools, career paths, legal considerations and practical learning roadmap.

Important safety note: Practice only on systems you own, intentionally vulnerable lab environments, authorized training platforms, or systems for which you have explicit permission to test. Never treat public accessibility as permission.

What Is Ethical Hacking?

Ethical hacking is the authorized process of examining a computer system, network, application or other technology environment for security weaknesses.

The goal is to identify problems before malicious attackers exploit them.

A simplified model is:

Organization
     ↓
Gives Authorization
     ↓
Ethical Hacker
     ↓
Tests Security
     ↓
Finds Weaknesses
     ↓
Reports Findings
     ↓
Organization Fixes Problems
     ↓
Security Is Retested

The ethical hacker therefore works as part of a defensive process.


What Does an Ethical Hacker Actually Do?

An ethical hacker may perform activities such as:

  • Discovering systems and services within an approved scope
  • Reviewing security configurations
  • Testing authentication and authorization controls
  • Assessing web applications
  • Checking for known weaknesses
  • Reviewing exposed services
  • Testing security controls
  • Analyzing evidence from security testing
  • Documenting vulnerabilities
  • Providing remediation recommendations

The exact tasks depend on the engagement and the authorized scope.


Ethical Hacking Is Not the Same as Criminal Hacking

Aspect Ethical Hacking Unauthorized Hacking
Permission Explicit authorization No authorization
Purpose Identify and reduce security risk May involve theft, disruption or unauthorized access
Scope Defined in advance May be undefined or intentionally exceeded
Reporting Findings are documented and reported No legitimate reporting obligation
Objective Improve security Potentially harm or misuse systems

The technical knowledge may overlap, but authorization, scope and intent fundamentally distinguish legitimate security testing from unauthorized intrusion.


What Is a White Hat Hacker?

A white hat hacker is commonly used to describe a security professional who conducts authorized security testing.

Other commonly used labels include:

  • Ethical hacker
  • Security tester
  • Penetration tester
  • Offensive security professional

These terms can overlap, but they do not always mean exactly the same thing.


What Is Black Hat Hacking?

Black hat hacking generally refers to malicious or unauthorized activity.

Examples of harmful behavior can include:

  • Unauthorized access
  • Credential theft
  • Data theft
  • Malware deployment
  • Unauthorized surveillance
  • Service disruption

These activities are fundamentally different from an authorized security assessment.


What Is a Gray Hat Hacker?

Gray hat is an informal term used for activity that falls between clearly authorized security testing and clearly malicious activity.

For example, someone might discover a vulnerability without having explicit permission to test the system and then contact the organization.

Even when the person has good intentions, lack of authorization can still create legal, contractual or operational problems.

The safest principle is simple:

Get permission before testing.

Ethical Hacking vs Penetration Testing

These terms are often used interchangeably, but they can describe different levels of scope.

Ethical hacking can be used as a broad term for authorized offensive-security activities.

Penetration testing is a more structured security-testing methodology designed to evaluate whether weaknesses can be used to compromise security under specified constraints.

NIST describes penetration testing as a methodology in which assessors attempt to circumvent security features under defined constraints and may simulate real-world attacks.

Ethical Hacking Penetration Testing
Broad practical term Specific structured testing activity
May include many security activities Usually has defined scope and objectives
Can involve research, assessment and testing Focused on demonstrating security weaknesses under agreed constraints
Term varies between organizations More formally defined in security standards and methodologies

What Are the Main Phases of Ethical Hacking?

A security assessment is generally more than simply running tools.

A simplified workflow is:

Planning & Authorization
        ↓
Reconnaissance
        ↓
Discovery & Enumeration
        ↓
Vulnerability Analysis
        ↓
Controlled Validation
        ↓
Risk Assessment
        ↓
Reporting
        ↓
Remediation
        ↓
Retesting

The exact terminology and methodology varies between organizations, assessment types and standards.


1. Planning and Authorization

This is one of the most important parts of the entire process.

Before technical testing begins, the tester should know:

  • Who authorized the assessment
  • Which systems are in scope
  • Which systems are out of scope
  • Which tests are allowed
  • Which tests are prohibited
  • When testing can occur
  • How sensitive data should be handled
  • How findings should be reported

A written scope helps prevent accidental testing of systems that were never included in the engagement.


2. Reconnaissance

Reconnaissance means collecting information about the target within the approved scope.

Depending on the engagement, information may include:

  • Domains
  • Subdomains
  • IP addresses
  • Technologies
  • Publicly documented services
  • Application functionality

In an authorized assessment, reconnaissance helps the tester understand the environment before deeper testing.


3. Discovery and Enumeration

Once the scope is understood, the tester can identify available systems and services.

Tools such as Nmap may be used during authorized network assessments.

For example, when testing your own machine:

nmap 127.0.0.1

This can help you understand what services are visible from a network perspective.

Discovery results should be interpreted carefully rather than automatically treated as vulnerabilities.


4. Vulnerability Analysis

After identifying systems and services, the tester examines them for weaknesses.

Examples of issues might include:

  • Outdated software
  • Weak configurations
  • Excessive permissions
  • Broken access controls
  • Insecure authentication
  • Unsafe application behavior
  • Exposed administrative interfaces

Vulnerability assessment and penetration testing are related but are not identical activities.


5. Controlled Validation

Finding a potential vulnerability is not always enough.

Where the engagement allows it, a tester may carefully validate whether a suspected weakness is actually exploitable.

This should be done:

  • Within the agreed scope
  • Using controlled methods
  • With minimal necessary impact
  • Without unnecessary data access or modification
  • According to the client's rules of engagement

NIST describes penetration testing as attempting to circumvent security features under defined constraints.


6. Risk Assessment

Not every discovered issue has the same impact.

A security professional considers factors such as:

  • Likelihood
  • Exploitability
  • Potential impact
  • Asset importance
  • Exposure
  • Existing security controls

This helps the organization prioritize remediation.


7. Reporting

Professional ethical hacking requires good reporting.

A security finding should generally explain:

Finding
   ↓
Evidence
   ↓
Affected Asset
   ↓
Impact
   ↓
Risk
   ↓
Recommended Fix
   ↓
Retest

A report might contain:

  • Executive summary
  • Scope
  • Methodology
  • Findings
  • Evidence
  • Risk information
  • Remediation recommendations
  • Retest results

8. Remediation and Retesting

Finding vulnerabilities is only part of the job.

The organization needs to fix the underlying issue.

After remediation, the tester may perform a follow-up test to determine whether the weakness has been properly addressed.

This creates a useful cycle:

Find
 ↓
Fix
 ↓
Retest
 ↓
Verify
 ↓
Monitor

Important Ethical Hacking Skills

A good ethical hacker needs more than knowledge of security tools.

1. Networking

Understand IP addresses, TCP, UDP, ports, DNS, routing, firewalls and HTTP.

2. Linux

Learn the command line, filesystems, permissions, processes and networking tools.

3. Windows

Learn Windows administration, PowerShell, services, permissions and enterprise concepts.

4. Programming

Python is particularly useful for scripting and automation. JavaScript and SQL are highly useful when studying web applications.

5. Web Technologies

Understand browsers, HTTP, APIs, cookies, sessions, authentication, databases and server-side applications.

6. Security Fundamentals

Learn vulnerabilities, risk, access control, cryptography, authentication and security architecture.

7. Communication

A security professional must be able to explain technical findings to both technical and non-technical audiences.


Programming Languages Useful for Ethical Hacking

Language Typical Use
Python Automation, scripting, data processing and security utilities
Bash Linux automation
PowerShell Windows administration and automation
JavaScript Web application understanding and security testing
SQL Database and application-security concepts

You do not need to master all of them at once.


Popular Ethical Hacking Tools

Tool Main Learning Area
Nmap Network discovery and service identification
Wireshark Network traffic analysis
Burp Suite Web application testing
OWASP ZAP Web security testing
Metasploit Controlled security validation
Nikto Web server security assessment
Gobuster Content and resource discovery in authorized assessments

Tools are only as useful as the person operating them.

A beginner who understands networking, HTTP, permissions and security concepts will usually learn these tools more effectively than someone who only memorizes commands.


What Is Kali Linux?

Kali Linux is a Linux distribution designed for security testing and related professional security tasks.

It includes many security tools in a convenient environment.

However, installing Kali Linux does not automatically make someone an ethical hacker.

You still need:

  • Networking knowledge
  • Linux skills
  • Security fundamentals
  • Web knowledge
  • Problem-solving ability
  • Practical experience

The operating system is a platform, not a replacement for knowledge.


What Is a Cybersecurity Lab?

A cybersecurity lab is a controlled environment where you can practice security concepts without interacting with unauthorized systems.

A simple setup can contain:

Host Computer
      |
      +----------------------+
      |                      |
   Linux VM              Windows VM
      |                      |
      +----------+-----------+
                 |
       Intentionally Vulnerable
            Practice Apps

Virtual machines are particularly useful because they allow learners to create isolated environments.


Safe Ethical Hacking Practice

Good practice targets include:

  • Your own computer
  • Your own virtual machines
  • Intentionally vulnerable applications
  • Capture-the-flag training environments
  • Training platforms that explicitly permit testing
  • Systems covered by a written authorization

OWASP's current security-testing materials emphasize explicit authorization before active security testing.


Why Authorization Matters

Imagine discovering a public website with a security weakness.

You might think:

"I should test it to prove the vulnerability."

That is not automatically appropriate.

Without permission, even actions performed with good intentions can create:

  • Service disruption
  • Privacy problems
  • Data exposure
  • Legal concerns
  • Contractual issues
  • Security alerts or incident investigations

The safer approach is to use a coordinated vulnerability disclosure process, a bug bounty program that explicitly covers the target, or obtain permission directly.


Ethical Hacking and Bug Bounty Programs

A bug bounty program is a program through which an organization invites security researchers to report vulnerabilities under defined rules.

A responsible researcher should always read the program's:

  • Scope
  • Out-of-scope systems
  • Testing restrictions
  • Data-handling rules
  • Reporting process
  • Safe-harbor language, where applicable

The existence of a bug bounty program does not mean every system belonging to the organization is automatically fair game.


Common Types of Ethical Hacking

Network Security Testing

Focuses on network exposure, services, architecture and controls.

Web Application Security Testing

Focuses on vulnerabilities in websites and web applications.

API Security Testing

Focuses on application programming interfaces, authentication, authorization, data exposure and request handling.

Mobile Application Security Testing

Examines mobile applications and their communication with backend systems.

Cloud Security Testing

Examines cloud configurations, identities, permissions and exposed services.

Wireless Security Testing

Assesses wireless network configurations and security controls under authorized conditions.

Social Engineering Assessments

Some organizations authorize controlled human-focused security assessments, such as phishing simulations or other awareness exercises.

These require especially clear rules because real people and organizational processes are involved.


Web Application Ethical Hacking

Web application security is a popular learning path.

Before testing applications, learn:

  • HTTP
  • HTML
  • JavaScript
  • Cookies
  • Sessions
  • Authentication
  • Authorization
  • APIs
  • Databases

OWASP's Web Security Testing Guide provides a structured reference for testing web applications and includes areas such as authentication, authorization, session management, input validation and other application-security concerns.


What Is the Role of Authorization Testing?

Authentication answers:

Who are you?

Authorization answers:

What are you allowed to do?

For example:

User → Can view own profile
Admin → Can manage users
Auditor → Can view reports

A security tester may assess whether those permissions are correctly enforced within the authorized application.

OWASP's current WSTG includes testing for authorization weaknesses such as users accessing resources or performing actions beyond their assigned permissions.


Ethical Hacking vs Vulnerability Assessment

These terms are also frequently confused.

Vulnerability Assessment Penetration Testing
Looks for potential weaknesses Attempts controlled validation of security weaknesses
Often broader coverage Often deeper testing of selected targets
May rely significantly on automated tools Usually combines tools with human analysis
Produces a set of identified or suspected issues Can demonstrate whether selected weaknesses can be used under the agreed test constraints

The exact boundaries vary by organization and methodology.


Manual Testing vs Automated Testing

Professional security testing uses both.

Automated Testing

Tools can quickly identify patterns across large numbers of systems or applications.

Manual Testing

A human tester can understand business logic, unusual application behavior and context that automated tools may not recognize correctly.

A mature security assessment therefore often follows:

Automation
    +
Human Analysis
    =
Better Security Assessment

What Makes a Good Ethical Hacker?

A strong ethical hacker is not simply someone who knows many commands.

Important characteristics include:

  • Curiosity
  • Strong technical fundamentals
  • Attention to detail
  • Problem-solving ability
  • Persistence
  • Clear documentation
  • Respect for scope
  • Professional communication
  • Responsible handling of information

Knowing when not to test something is an important professional skill.


Cybersecurity Certifications for Ethical Hacking

Certifications can help structure learning and demonstrate knowledge, but they do not replace practical skills.

Potential certification paths can include:

  • Entry-level cybersecurity certifications
  • Network/security fundamentals certifications
  • Hands-on penetration-testing certifications
  • Application-security certifications
  • Advanced offensive-security certifications

Before choosing one, compare:

  • Current syllabus
  • Hands-on requirements
  • Exam format
  • Prerequisites
  • Cost
  • Renewal requirements
  • Relevance to your target role

Career Options Related to Ethical Hacking

Ethical hacking knowledge can lead toward several security career areas.

Career Area Common Focus
Penetration Tester Authorized security testing
Application Security Secure software and web applications
Security Engineer Security architecture and controls
SOC Analyst Detection, monitoring and incident analysis
Red Team Security Authorized adversary simulation
Cloud Security Cloud infrastructure and identity security

Cybersecurity Skills Roadmap for Ethical Hacking

Computer Fundamentals
        ↓
Networking
        ↓
Linux
        ↓
Windows
        ↓
Python + SQL + JavaScript
        ↓
Cybersecurity Fundamentals
        ↓
Web Technology
        ↓
Nmap + Wireshark
        ↓
Web Security
        ↓
Burp Suite / OWASP
        ↓
Security Labs
        ↓
Projects
        ↓
Reporting
        ↓
Specialization

Beginner Ethical Hacking Projects

You can build projects without attacking real-world systems.

Project 1: Local Network Inventory

Create an inventory of your own lab machines and document their services.

Project 2: Log Analysis Tool

Build a Python program that reads a sample log and identifies repeated failed authentication events.

Project 3: Security Headers Checker

Create a tool that checks HTTP response headers for your own website or an authorized test application.

Project 4: File Integrity Monitor

Create a small application that calculates file hashes and detects unexpected changes.

Project 5: Vulnerability Report

Set up an intentionally vulnerable application and produce a professional report explaining findings and remediation.


How to Build an Ethical Hacking Portfolio

Your portfolio can contain:

  • GitHub repositories
  • Lab reports
  • Security write-ups
  • Network analysis exercises
  • Web-security projects
  • Python security scripts
  • CTF write-ups
  • Security research notes

For every project, include:

Objective
Environment
Scope
Methodology
Tools
Observations
Findings
Impact
Remediation
Lessons Learned

This shows employers that you understand the complete security-testing process.


Ethical Hacking and Responsible Disclosure

Suppose you discover a vulnerability in an application you are explicitly authorized to test.

A responsible process could look like:

Discover
   ↓
Verify Safely
   ↓
Document
   ↓
Report Privately
   ↓
Allow Remediation
   ↓
Retest
   ↓
Close Finding

Do not unnecessarily disclose sensitive technical details before an organization has had a reasonable opportunity to address the issue.


Common Ethical Hacking Myths

Myth 1: Ethical Hackers Just Run Tools

Professional testing requires analysis, judgment, communication and reporting.

Myth 2: Kali Linux Makes You a Hacker

Kali is a security-focused operating system. It does not replace knowledge or experience.

Myth 3: Knowing 100 Tools Makes You an Expert

Understanding systems is more important than collecting tool names.

Myth 4: Every Open Port Is a Vulnerability

An open port usually indicates an accessible service, not automatically a security flaw.

Myth 5: More Aggressive Testing Is Always Better

Security testing should follow the agreed scope and minimize unnecessary impact.

Myth 6: Ethical Hacking Is Only About Attacking

Understanding defenses, remediation and secure design is equally valuable.


Ethical Hacking vs Cybersecurity

Cybersecurity is the broader field.

Ethical hacking is one part of it.

Cybersecurity
│
├── Network Security
├── Application Security
├── Cloud Security
├── SOC / Detection
├── Incident Response
├── Digital Forensics
├── GRC
├── Identity Security
└── Ethical Hacking
       ├── Penetration Testing
       ├── Red Teaming
       └── Security Testing

This is why someone interested in ethical hacking should still study defensive security concepts.


How Long Does It Take to Learn Ethical Hacking?

There is no universal timeline.

Someone who already understands networking, Linux and programming will progress differently from someone starting with no technical background.

A realistic progression is:

Stage Primary Focus
BeginnerComputers, networking, Linux and security basics
DevelopingWeb security, tools and labs
IntermediateSpecialization and deeper testing
AdvancedComplex environments, reporting and specialized security work

Beginner Ethical Hacking Study Routine

A balanced daily routine might look like:

30 min → Theory
30 min → Networking/Linux
60 min → Authorized Lab
30 min → Notes
30 min → Project or Review

Adjust the schedule to your available time.

Consistency is more useful than trying to learn everything at once.


What Should You Learn Before Ethical Hacking?

Learn these foundations first:

  • Computer networking
  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • Linux
  • Windows basics
  • Python fundamentals
  • SQL basics
  • Authentication and authorization
  • Basic cryptography

What Should You Learn After Ethical Hacking Basics?

Once the fundamentals are comfortable, choose a specialization such as:

  • Web application security
  • API security
  • Network penetration testing
  • Active Directory security
  • Cloud security
  • Red team operations
  • Application security
  • Security research

Choosing a specialization prevents you from trying to master the entire cybersecurity industry at the same time.


Frequently Asked Questions

1. What is ethical hacking in simple words?

Ethical hacking is authorized security testing performed to find weaknesses so they can be fixed before malicious attackers exploit them.

2. Is ethical hacking legal?

Authorized security testing can be legitimate, but permission and scope are critical. You should only test systems that you own or are explicitly authorized to assess.

3. What is the difference between a hacker and an ethical hacker?

The term hacker can describe someone skilled at finding or working with computer systems, while an ethical hacker performs security activities with authorization and a legitimate security purpose.

4. Is ethical hacking the same as penetration testing?

Not necessarily. Ethical hacking is often used as a broad term for authorized offensive-security work, while penetration testing is a more specific structured security-testing methodology.

5. Do I need programming for ethical hacking?

You do not need to be an expert programmer, but Python, Bash, PowerShell, SQL and JavaScript can significantly improve your capabilities.

6. Is Kali Linux necessary?

No. Kali Linux is useful for security work and learning, but cybersecurity fundamentals can be learned on other operating systems as well.

7. Can I practice ethical hacking on Google or other public websites?

Do not assume that a public website is an authorized target. Use your own systems, security labs or targets with explicit permission.

8. Are open ports vulnerabilities?

No. An open port generally indicates that a service is accessible. You need additional analysis to determine whether that exposure creates a security problem.

9. Is ethical hacking only about finding vulnerabilities?

No. It also involves understanding systems, validating findings, assessing impact, documenting evidence and helping organizations remediate weaknesses.

10. What is the best tool for ethical hacking?

There is no single best tool for every situation. Different tools are designed for different tasks, such as network discovery, packet analysis, web testing and vulnerability assessment.

11. Can ethical hackers work without certifications?

Certification requirements vary by employer and role. Practical skills, technical understanding, projects and communication ability can all be important.

12. What should a beginner learn first?

Start with networking, Linux, Windows fundamentals, programming basics and core cybersecurity concepts before moving into advanced security tooling.


Final Thoughts

Ethical hacking is not about breaking into random systems.

It is about authorized security assessment.

A professional ethical hacker needs to understand:

How systems work → How weaknesses occur → How to test safely → How to explain the risk → How to fix the problem

The strongest beginners build a foundation in networking, Linux, Windows, programming and web technologies before becoming heavily dependent on specialized tools.

Remember the most important rule throughout your learning journey:

Never test a system simply because you can access it. Test only when you have authorization.

With that mindset, ethical hacking becomes a valuable part of cybersecurity rather than simply a collection of hacking commands.


Recommended Reading on CodeWithAV

Tip: Replace the homepage links above with the exact article URLs after the related CodeWithAV posts are published.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

Nmap Tutorial for Beginners: Complete Guide to Network Scanning

Nmap Tutorial for Beginners: Complete Guide to Network Scanning

When you start learning cybersecurity, one of the first tools you are likely to encounter is Nmap.

Nmap is commonly used for network discovery, port scanning, service identification and security auditing. It is useful to administrators, security professionals, penetration testers and students learning networking.

But many beginners make the mistake of learning Nmap by memorizing commands without understanding what those commands actually do.

This tutorial takes a different approach.

We will first understand:

  • What Nmap is
  • What a port is
  • What Nmap actually scans
  • How port states work
  • How host discovery works
  • How to perform basic scans
  • How to identify services
  • How to interpret Nmap output
  • How to save scan results
  • How to build a safe Nmap practice lab

Important: Only scan systems and networks that you own or have explicit permission to test. The Nmap Project itself recommends obtaining authorization before scanning a network. It also provides scanme.nmap.org as an authorized practice target specifically for Nmap scans, with restrictions described in its legal guidance. Do not use that authorization for exploitation or denial-of-service testing. (Official Nmap Legal Guidance)


What Is Nmap?

Nmap stands for Network Mapper.

According to the official Nmap documentation, it is a free and open-source tool for network exploration and security auditing. It can determine information such as available hosts, services and versions, operating-system characteristics and packet-filtering behavior. (Official Nmap Introduction)

A simplified example is:

Your Computer
      |
      | Nmap
      ↓
Target System
      |
      ├── Is the host reachable?
      ├── Which ports are open?
      ├── What services are running?
      └── What information can be identified?

Nmap is therefore much more than a simple "port scanner."


Why Is Nmap Important in Cybersecurity?

Before securing a network, you need to understand what is exposed.

For example, imagine a server has these ports available:

22/tcp   SSH
80/tcp   HTTP
443/tcp  HTTPS
3306/tcp MySQL

That immediately gives an administrator useful information about the services that may need to be reviewed.

Security professionals can use authorized scanning to help answer questions such as:

  • Which hosts are active?
  • Which ports are reachable?
  • Which services appear to be running?
  • Which service versions are visible?
  • Which systems have unexpected exposure?

The official Nmap guide describes network inventory, security auditing and service discovery among its practical uses. (Nmap Network Scanning)


What Is a Port?

Before using Nmap, you need to understand ports.

A networked computer can run multiple services. Ports provide a way for network traffic to be associated with those services.

Some commonly known ports include:

Port Common Service
22SSH
25SMTP
53DNS
80HTTP
110POP3
143IMAP
443HTTPS
3306MySQL
5432PostgreSQL
6379Redis

A port number alone does not guarantee which service is actually running there. Services can be configured to use non-standard ports.

Nmap's service and version detection features are designed to identify what is actually listening rather than relying only on a port-number assumption. (Nmap Service and Version Detection)


Nmap Installation

Nmap runs on major desktop operating systems, including Linux, Windows and macOS. (Nmap Official Guide)

Ubuntu / Debian

sudo apt update
sudo apt install nmap

Fedora-Based Systems

sudo dnf install nmap

Arch Linux

sudo pacman -S nmap

Windows

Download Nmap from the official Nmap website rather than an unofficial software mirror.

Official Nmap Download Page

After installation, verify it:

nmap --version

You should see the installed Nmap version and related information.


Basic Nmap Syntax

The general structure is:

nmap [options] target

For example:

nmap 192.168.1.10

Here:

  • nmap = program
  • 192.168.1.10 = target

Options modify how Nmap performs the scan.


Start With Your Own Computer

The safest way for a beginner to start is to scan the local system.

Try:

nmap localhost

You can also use:

nmap 127.0.0.1

These refer to the local host in common configurations.

This lets you experiment without scanning someone else's machine.


Understanding Nmap Output

A basic scan might produce output resembling:

Starting Nmap

PORT    STATE    SERVICE
22/tcp  open     ssh
80/tcp  open     http
443/tcp open     https

Nmap done

The important columns are:

Column Meaning
PORTPort number and protocol
STATEObserved state of the port
SERVICEProbable service associated with the port

Nmap Port States

Nmap reports several different port states.

1. Open

An open port means an application is listening and accepting connections or packets associated with that port.

2. Closed

A closed port is reachable, but no application is listening on it at the time of the scan.

3. Filtered

A filtered port means Nmap cannot determine whether it is open because packet filtering prevents it from determining the state.

4. Unfiltered

Unfiltered means the port is accessible but Nmap cannot determine from the scan whether it is open or closed for that particular scan method.

5. Open|Filtered

Nmap may use open|filtered when it cannot determine whether the port is open or filtered.

6. Closed|Filtered

Some scan types can also produce closed|filtered where the distinction cannot be determined.

Understanding these states is much more important than simply looking for the word "open."


Basic Scan

The simplest Nmap scan is:

nmap 127.0.0.1

Nmap performs a basic scan of the target and reports discovered ports.

Use this first to become familiar with the output.


Scan a Specific Port

You can specify a particular port:

nmap -p 80 127.0.0.1

To scan another port:

nmap -p 443 127.0.0.1

This is useful when you already know which service you want to check.


Scan Multiple Ports

You can specify several ports separated by commas:

nmap -p 22,80,443 127.0.0.1

You can also specify a range:

nmap -p 20-100 127.0.0.1

For lab environments, port ranges are useful for understanding how exposed services appear in a scan.


Scan All TCP Ports

Nmap's common default scan does not examine every possible TCP port.

You can request all TCP ports with:

nmap -p- 127.0.0.1

This scans TCP ports 1 through 65535.

Use broad scans primarily in systems you own or authorized lab environments because they generate more traffic and can take longer.


Scan a Network Range

Nmap can also work with multiple targets.

For example, in your own home lab:

nmap 192.168.1.0/24

This represents a CIDR network range.

Before scanning a network range, verify that the entire range belongs to your network or that you have authorization to assess it.


Host Discovery

Sometimes you first want to know which systems are reachable.

Nmap provides host-discovery capabilities.

A common example is:

nmap -sn 192.168.1.0/24

The -sn option performs host discovery without a port scan.

This can be useful for inventorying systems in an authorized network.


Why Host Discovery Matters

Imagine a lab network containing:

192.168.1.10 → Linux Server
192.168.1.11 → Windows VM
192.168.1.12 → Web Server
192.168.1.13 → Database VM

A host-discovery scan can help you identify systems that respond to the discovery methods being used.

Remember that network controls can cause some hosts not to respond to particular discovery probes.


Service and Version Detection

Finding an open port is only the beginning.

Suppose Nmap reports:

80/tcp open http

You may want to know what web server is actually running.

Use:

nmap -sV 127.0.0.1

The -sV option enables service/version detection.

According to the official documentation, Nmap uses service probes to identify services and, where possible, application names and version information. (Official Service and Version Detection Guide)

Example output may look like:

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH
80/tcp open  http    Apache

The exact results depend on the target.


Why Version Detection Is Useful

Imagine finding:

80/tcp open http

That tells you a web service is available.

But:

80/tcp open http Apache

gives you additional information about the service.

Version information can help administrators identify outdated software and determine which systems require maintenance or security review.


Operating System Detection

Nmap can attempt operating-system detection with:

sudo nmap -O 127.0.0.1

The -O option enables OS detection.

Nmap attempts to infer characteristics of the target operating system from responses to its probes.

OS detection may not always identify the system perfectly. Network filtering, virtualization and other factors can affect the results.


Aggressive Detection

Nmap also provides the -A option.

nmap -A 127.0.0.1

According to Nmap's documentation, -A enables several advanced detection features, including OS detection, version detection, script scanning and traceroute-related functionality. (Nmap Reference Guide)

Because this performs more checks, it is best used in your own lab or an explicitly authorized environment.


Nmap Default Scripts

Nmap includes the Nmap Scripting Engine (NSE).

NSE allows scripts to extend Nmap's capabilities for tasks such as service discovery, security checks and information gathering.

A common command is:

nmap -sC 127.0.0.1

The -sC option runs the default category of NSE scripts.

Use scripting only where you are authorized to perform the corresponding checks.

The official Nmap reference guide documents NSE as a major part of the tool's capabilities. (Nmap Reference Guide)


TCP SYN Scan

One of Nmap's well-known scanning methods is the TCP SYN scan:

sudo nmap -sS 127.0.0.1

The -sS option performs a TCP SYN scan.

At a conceptual level, Nmap uses TCP behavior to infer whether ports are open, closed or filtered.

You do not need to understand the packet-level details immediately. First learn how to interpret the resulting port states.


TCP Connect Scan

Nmap can also perform a TCP connect scan:

nmap -sT 127.0.0.1

The -sT method uses the operating system's normal connection mechanism.

The actual scanning method available or selected can depend on privileges and operating-system behavior.


UDP Scanning

Nmap can also scan UDP ports.

sudo nmap -sU 127.0.0.1

UDP scanning can be slower and can produce states such as open|filtered because UDP does not use the same connection process as TCP.

Only perform UDP scans against systems that you are authorized to assess.


Scan a Specific UDP Port

sudo nmap -sU -p 53 127.0.0.1

This is useful when testing a service in your own lab.


Fast Scan

Nmap provides a fast-scan option:

nmap -F 127.0.0.1

The -F option reduces the set of ports scanned compared with broader scans.

This is useful when you want a quick initial check.


Increase Scan Speed

Nmap provides timing templates such as:

nmap -T4 127.0.0.1

The timing templates range from slower and more cautious behavior to faster scanning.

Faster does not always mean better.

Increasing scan speed can affect accuracy, network load and the way network defenses respond.

Use aggressive timing carefully and primarily in controlled environments.


Disable Host Discovery

Sometimes you already know a target is online and want Nmap to skip host discovery.

nmap -Pn 192.168.1.10

The -Pn option treats the host as online instead of relying on host-discovery checks to decide whether to scan it.

This can be useful when discovery traffic is filtered.


Scan Only Selected TCP Ports

You can specify a list:

nmap -p 22,80,443 127.0.0.1

Or a range:

nmap -p 1-1024 127.0.0.1

This is a good way to practice without immediately scanning every port.


Scan Top Ports

Nmap also supports selecting a number of commonly used ports:

nmap --top-ports 20 127.0.0.1

You can change the number according to the needs of your authorized lab test.


Verbose Mode

Verbose mode provides more information while the scan is running.

nmap -v 127.0.0.1

For even more output, Nmap supports higher verbosity levels:

nmap -vv 127.0.0.1

This can help beginners understand what the tool is doing.


Save Nmap Results to a File

Saving scan results is important for documentation and comparison.

Normal Output

nmap -oN scan.txt 127.0.0.1

XML Output

nmap -oX scan.xml 127.0.0.1

Grepable Output

nmap -oG scan.gnmap 127.0.0.1

All Major Output Formats

nmap -oA myscan 127.0.0.1

The -oA option saves output in multiple formats using the specified base filename.


Why Save Scan Results?

Imagine you scan your own lab today:

22/tcp open ssh
80/tcp open http

After you change the server configuration, you scan again:

80/tcp open http

You can compare the two reports and confirm that SSH is no longer exposed.

This makes Nmap useful for network inventory and security validation, not just one-time experiments.


Scanning Multiple Hosts

You can specify multiple IP addresses:

nmap 192.168.1.10 192.168.1.11 192.168.1.12

You can also use a host range in an authorized environment:

nmap 192.168.1.10-20

Always verify that the targets are part of your authorized scope.


Scan a Domain You Are Authorized to Test

Nmap can accept hostnames:

nmap example.com

However, the fact that a website is publicly accessible does not mean that you have permission to scan it.

For learning, your safest options are:

  • Your own computer
  • Your own server
  • Your own home lab
  • Virtual machines
  • Dedicated security-training targets
  • Targets explicitly authorized for scanning

The Official scanme.nmap.org Practice Target

The Nmap Project provides scanme.nmap.org as a special target for practicing Nmap.

The official legal guide says this authorization is for Nmap scanning and does not extend to exploit testing or denial-of-service attacks. It also asks users not to initiate more than a dozen scans against the host per day to conserve bandwidth. (Nmap Legal Issues)

A basic authorized example is:

nmap scanme.nmap.org

Keep your practice limited to the permission provided by the Nmap Project.


A Beginner Nmap Workflow

Instead of randomly trying commands, follow a logical process.

1. Identify authorized target
            ↓
2. Check host availability
            ↓
3. Perform basic port scan
            ↓
4. Identify open ports
            ↓
5. Detect services
            ↓
6. Investigate configuration
            ↓
7. Document findings
            ↓
8. Fix unnecessary exposure
            ↓
9. Scan again

This workflow is much closer to how network assessment becomes useful in practice.


Example: Building a Small Local Lab

Suppose you have one Linux machine running locally.

First find your local addresses:

ip addr

Then check listening services:

ss -tuln

Now compare the operating system's local information with Nmap:

nmap 127.0.0.1

Then try service detection:

nmap -sV 127.0.0.1

This gives you a simple exercise:

Can you explain why each port reported by Nmap is open and which local service is responsible for it?

Nmap and ss: Why Use Both?

ss shows local socket information from the system.

Nmap approaches the target from the network perspective.

This distinction is valuable.

Tool Perspective
ss Local system
Nmap Network view of the target

Comparing both can help you understand firewall behavior and network exposure.


Nmap vs Netstat

Older Linux tutorials often introduce netstat.

Modern Linux systems frequently use ss instead.

Nmap serves a different purpose because it is designed for network discovery and scanning rather than simply displaying local socket information.


Nmap vs Ping

These tools answer different questions.

Ping:

ping 192.168.1.10

Primarily tests basic IP-level reachability using ICMP echo behavior when permitted.

Nmap:

nmap 192.168.1.10

Can investigate ports, services and other network characteristics.

A host can be reachable while not responding to ping, because network controls may filter ICMP.


Common Nmap Options Cheat Sheet

Option Purpose
-snHost discovery without a port scan
-sSTCP SYN scan
-sTTCP connect scan
-sUUDP scan
-sVService/version detection
-OOS detection
-ASeveral advanced detection features
-sCDefault NSE scripts
-pSpecify ports
-p-Scan all TCP ports
-FFast scan
-PnSkip host discovery assumption
-vVerbose output
-oNNormal output file
-oXXML output
-oGGrepable output
-oASave multiple output formats
--top-portsScan selected common ports
-T4Use a faster timing template

Useful Beginner Commands

Basic Scan

nmap 127.0.0.1

Specific Ports

nmap -p 22,80,443 127.0.0.1

Service Detection

nmap -sV 127.0.0.1

OS Detection

sudo nmap -O 127.0.0.1

Default Scripts

nmap -sC 127.0.0.1

All TCP Ports

nmap -p- 127.0.0.1

Save Results

nmap -oA lab-scan 127.0.0.1

How to Read an Nmap Scan Like a Beginner

Suppose you receive:

PORT     STATE  SERVICE
22/tcp   open   ssh
80/tcp   open   http
443/tcp  open   https
8080/tcp open   http-proxy

Do not immediately think:

"I found four vulnerabilities."

You have not.

You have found four network services that appear accessible.

The next questions should be:

  • Are these services expected?
  • Who needs them?
  • Are they securely configured?
  • Are the versions current?
  • Should any service be restricted?
  • Is the exposure intentional?

This is the difference between scanning and security analysis.


Nmap Does Not Automatically Mean Vulnerability

This is an important concept.

An open port is not automatically a vulnerability.

For example:

443/tcp open https

This may simply mean the server intentionally provides a secure web service.

The security question is whether the service is appropriately configured, maintained and exposed.


Common Beginner Mistakes With Nmap

1. Scanning Random Public IP Addresses

Do not assume that a publicly reachable system is available for testing.

2. Using Aggressive Options Immediately

Start with simple scans and learn how to interpret the results.

3. Treating Every Open Port as a Vulnerability

Open services can be completely legitimate.

4. Ignoring Scope

In professional security assessments, scan only the systems and address ranges included in the authorized scope.

5. Focusing on Commands Instead of Networking

Understanding TCP, UDP, IP addresses, ports, routing and firewalls makes Nmap much easier to understand.

6. Not Saving Results

Always document significant authorized assessments.

7. Ignoring False Positives and Limitations

Nmap makes inferences from network responses. Detection results are not perfect and should be interpreted carefully.


Nmap and Firewalls

Firewalls can affect scan results.

For example, a firewall may:

  • Allow traffic
  • Reject traffic
  • Drop traffic silently
  • Allow only certain source addresses
  • Allow only particular ports

This can produce different Nmap states.

For example:

Port A → open
Port B → closed
Port C → filtered

Understanding why the results differ requires networking knowledge.


How Nmap Fits Into a Security Assessment

A simplified authorized security workflow may look like:

Scope
  ↓
Asset Discovery
  ↓
Port Scanning
  ↓
Service Identification
  ↓
Configuration Review
  ↓
Vulnerability Assessment
  ↓
Risk Analysis
  ↓
Remediation
  ↓
Verification
  ↓
Report

Nmap is mainly useful during discovery and service-identification stages, though its other capabilities can support additional assessment tasks.


Mini Nmap Lab for Beginners

Try this sequence on your own machine.

Step 1 — Check Local Services

ss -tuln

Step 2 — Perform Basic Nmap Scan

nmap 127.0.0.1

Step 3 — Scan Common Ports

nmap --top-ports 20 127.0.0.1

Step 4 — Detect Services

nmap -sV 127.0.0.1

Step 5 — Scan All TCP Ports

nmap -p- 127.0.0.1

Step 6 — Save Results

nmap -oA first-lab-scan 127.0.0.1

Step 7 — Document What You Learned

Write down:

  • Which ports were open?
  • Which services were identified?
  • Which ports did you expect?
  • Were any unexpected services visible?
  • What configuration changes could reduce unnecessary exposure?

Beginner Nmap Learning Roadmap

Networking Fundamentals
       ↓
TCP / UDP
       ↓
Ports and Services
       ↓
Basic Nmap
       ↓
Host Discovery
       ↓
Port States
       ↓
Service Detection
       ↓
OS Detection
       ↓
NSE
       ↓
Output and Reporting
       ↓
Authorized Security Labs

What Should You Learn Before Nmap?

For better results, learn these concepts first:

  • IP addresses
  • TCP and UDP
  • Ports
  • DNS
  • Routing
  • Firewalls
  • Network interfaces
  • Basic Linux commands

Our earlier CodeWithAV articles on networking and Linux can help build this foundation.


What Should You Learn After Nmap?

Once you understand basic Nmap, continue with:

  • Wireshark
  • Web application security
  • Burp Suite
  • OWASP fundamentals
  • Vulnerability management
  • Security logging
  • Network defense
  • Penetration-testing methodology

The goal should be to understand why a result matters, not just how to produce it.


Frequently Asked Questions

1. Is Nmap a hacking tool?

Nmap is a network exploration and security-auditing tool. It is used by administrators and security professionals for legitimate network discovery, inventory and testing. Whether its use is appropriate depends on authorization and how it is used.

2. Is Nmap free?

Yes. Nmap is free and open-source software. The official Nmap site provides downloads and documentation. (Nmap Official Website)

3. Is Nmap legal?

The legality of scanning depends on the jurisdiction, circumstances and authorization involved. The Nmap Project recommends securing written authorization before scanning networks and explains that users should understand applicable rules and provider policies. (Nmap Legal Guidance)

4. Can I scan my own computer?

Yes. Scanning systems you own or are explicitly authorized to test is the appropriate way to practice.

5. What does an open port mean?

An open port indicates that Nmap has determined that an application is listening and accepting relevant network communication on that port.

6. Does an open port mean the system is vulnerable?

No. An open port simply indicates an accessible service. You need additional analysis to determine whether a service is unnecessarily exposed, outdated or insecurely configured.

7. What is the difference between -sS and -sT?

-sS performs a TCP SYN scan, while -sT performs a TCP connect scan. The exact behavior and privilege requirements depend on the operating system and environment.

8. What is -sV?

-sV enables service and version detection, allowing Nmap to probe discovered services and attempt to identify the application and version.

9. What is -O?

-O enables operating-system detection. Nmap attempts to infer the target's operating-system characteristics from network responses.

10. What is NSE?

NSE stands for Nmap Scripting Engine. It allows scripts to extend Nmap for additional discovery, information gathering and security-related checks.

11. What is the safest Nmap target for beginners?

Your own computer or a deliberately created virtual-machine lab is the safest starting point. The Nmap Project also provides scanme.nmap.org as an explicitly authorized Nmap practice target with usage restrictions. (Official Scanme Guidance)

12. Can Nmap crash a server?

Most ordinary scans are designed for network discovery and auditing, but unexpected behavior or fragile systems can create problems. The safest approach is to scan authorized systems and begin with conservative tests.


Final Thoughts

Nmap is one of the most useful tools for learning the relationship between networking and cybersecurity.

But learning Nmap is not about memorizing hundreds of commands.

Start with a few fundamental concepts:

Host → Port → Service → Version → Configuration → Risk → Remediation

Practice first on 127.0.0.1, your own virtual machines and authorized training environments.

Once you understand what Nmap is actually telling you, commands such as -sV, -O, -p, -sn and -oA become much easier to understand.

Most importantly, remember that network visibility is not the same thing as vulnerability.

A professional security mindset asks:

What is exposed, why is it exposed, is that exposure necessary, and how can it be secured?

That is the mindset worth developing as you continue your cybersecurity journey.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV posts after publication.


Official Nmap Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.