penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration Testing Roadmap 2026: Step-by-Step Guide for Beginners

Penetration testing is one of the most interesting areas of cybersecurity.

It combines networking, Linux, Windows, programming, web technologies, vulnerability analysis, security testing and technical reporting.

But there is one major problem for beginners:

What should I learn first, and what should I learn next?

Many beginners start with Kali Linux, install several security tools and immediately jump into advanced tutorials.

That approach can create the illusion of progress without building the underlying knowledge needed to understand what the tools are actually doing.

A better approach is to build your skills in layers:

Computer Fundamentals
        ↓
Networking
        ↓
Linux + Windows
        ↓
Programming
        ↓
Web Technologies
        ↓
Security Fundamentals
        ↓
Nmap + Traffic Analysis
        ↓
Web Security
        ↓
Hands-on Labs
        ↓
Penetration Testing Methodology
        ↓
Specialization
        ↓
Reporting
        ↓
Portfolio

This guide explains that roadmap in detail.

Important: Penetration testing must be authorized. Practice only on systems you own, deliberately vulnerable labs, training environments, bug-bounty targets explicitly within scope, or systems covered by written permission.

What Is Penetration Testing?

Penetration testing, often called pentesting, is a structured form of security testing in which authorized testers evaluate whether weaknesses in a system can be used to compromise security under defined constraints.

NIST defines penetration testing as a methodology where assessors attempt to circumvent or defeat security features under specified constraints. NIST SP 800-115 also provides guidance for planning, conducting and evaluating technical security tests. (NIST Penetration Testing)

A simplified process is:

Authorization
      ↓
Scope
      ↓
Discovery
      ↓
Enumeration
      ↓
Vulnerability Analysis
      ↓
Controlled Validation
      ↓
Reporting
      ↓
Remediation
      ↓
Retesting

What Does a Penetration Tester Do?

A penetration tester may be responsible for:

  • Understanding the authorized scope
  • Discovering systems and services
  • Analyzing applications
  • Identifying vulnerabilities
  • Validating selected findings
  • Assessing potential impact
  • Documenting evidence
  • Writing security reports
  • Providing remediation guidance
  • Performing retesting after fixes

The exact responsibilities vary by organization and specialization.


Penetration Testing Roadmap at a Glance

Stage Main Focus
1Computer fundamentals
2Networking
3Linux
4Windows
5Programming and scripting
6Web technologies
7Cybersecurity fundamentals
8Security tools
9Hands-on labs
10Testing methodology
11Specialization
12Reporting and portfolio

Stage 1: Learn Computer Fundamentals

Before learning penetration testing, understand how computers actually work.

Learn:

  • CPU
  • RAM
  • Storage
  • Operating systems
  • Processes
  • Files and directories
  • Users and permissions
  • Applications
  • Client-server architecture

Questions to Understand

  • What is a process?
  • What is a service?
  • How does an application communicate with another system?
  • What is a user account?
  • What are file permissions?
  • What happens when a program starts?

You do not need to become a hardware engineer.

The goal is to understand the basic environment in which security problems occur.


Stage 2: Master Networking

Networking is one of the most important foundations for penetration testing.

Learn these concepts:

  • IPv4
  • IPv6 basics
  • MAC addresses
  • TCP
  • UDP
  • Ports
  • DNS
  • DHCP
  • HTTP
  • HTTPS
  • Routing
  • NAT
  • Firewalls
  • VPNs
  • Subnetting

You should eventually be comfortable explaining:

User
 ↓
DNS
 ↓
IP Address
 ↓
Router
 ↓
TCP Connection
 ↓
Port
 ↓
Service
 ↓
Application

Without this knowledge, tools such as Nmap can become little more than a collection of commands.


Stage 3: Learn Linux

Linux is an important operating system for security learners.

Learn:

  • Filesystem structure
  • File permissions
  • Users and groups
  • Processes
  • Services
  • Networking
  • Logs
  • SSH
  • Shell scripting

Essential Linux Commands

pwd
ls
cd
mkdir
cp
mv
rm
cat
less
grep
find
chmod
chown
ps
top
ip
ss
curl
ssh
journalctl

Learning these commands will make later security tooling much easier.


Stage 4: Learn Windows

Penetration testing is not limited to Linux systems.

Many enterprise environments use Windows extensively.

Learn:

  • Windows users and groups
  • NTFS permissions
  • Processes
  • Services
  • PowerShell
  • Event Viewer
  • Windows Defender
  • Registry basics
  • Authentication
  • Active Directory fundamentals

Understanding Windows becomes especially important if you want to explore enterprise penetration testing.


Stage 5: Learn Programming and Scripting

You do not need to become an expert programmer before starting penetration testing.

However, scripting becomes extremely useful as your skills grow.

Technology Why Learn It?
PythonAutomation, APIs, scripts and data processing
BashLinux automation
PowerShellWindows administration and automation
SQLDatabase and application security
JavaScriptWeb application understanding

For most beginners, Python + Bash + SQL + basic JavaScript is a useful combination.


Stage 6: Learn Web Technologies

If you want to test websites or APIs, you must first understand how they work.

Learn:

  • HTML
  • CSS basics
  • JavaScript basics
  • HTTP requests
  • HTTP responses
  • Headers
  • Cookies
  • Sessions
  • Authentication
  • Authorization
  • REST APIs
  • JSON
  • Databases

A simplified web architecture looks like:

Browser
   ↓
Frontend
   ↓
API / HTTP
   ↓
Backend
   ↓
Database

Security testing becomes much easier when you understand each layer.


Stage 7: Learn Cybersecurity Fundamentals

Before studying specific vulnerabilities, understand the basic language of security.

Learn:

  • Confidentiality
  • Integrity
  • Availability
  • Authentication
  • Authorization
  • Accounting and logging
  • Least privilege
  • Defense in depth
  • Threats
  • Vulnerabilities
  • Risk

Understand the CIA Triad

Confidentiality
       /\
      /  \
     /    \
    /      \
Integrity--Availability

These concepts provide the foundation for understanding why security weaknesses matter.


Stage 8: Learn Authentication and Authorization

This is particularly important for web and API security.

Authentication: Who are you?

Authorization: What are you allowed to do?

Study:

  • Passwords
  • MFA
  • Sessions
  • Cookies
  • Tokens
  • Roles
  • Permissions
  • Access-control models

Many serious application-security problems involve incorrect authorization rather than simply weak passwords.


Stage 9: Learn Cryptography Basics

You do not need advanced mathematics to begin.

Understand:

  • Encryption
  • Decryption
  • Symmetric cryptography
  • Asymmetric cryptography
  • Hashing
  • Digital signatures
  • Certificates
  • Public/private keys
  • TLS basics

You should be able to explain why passwords should be protected using appropriate password-hashing mechanisms rather than simple reversible encryption.


Stage 10: Learn Vulnerabilities

Now start studying common vulnerability classes.

Important areas include:

  • Broken access control
  • Injection
  • Authentication failures
  • Security misconfiguration
  • Cryptographic failures
  • Insecure design
  • Outdated components
  • Session-management weaknesses
  • Server-side request issues

For web security, OWASP's Web Security Testing Guide provides a structured reference for application testing. OWASP currently lists version 4.2 as the latest released WSTG version while version 5.0 is under development. (OWASP WSTG)


Stage 11: Learn Nmap

Nmap is commonly used for network discovery and service identification.

Start with your local lab:

nmap 127.0.0.1

Then learn:

nmap -p 22,80,443 127.0.0.1

nmap -sV 127.0.0.1

nmap -p- 127.0.0.1

nmap -oA lab-scan 127.0.0.1

Learn what the results mean before adding more advanced options.


Stage 12: Learn Wireshark

Wireshark helps you inspect network traffic.

Learn:

  • Packets
  • Frames
  • TCP handshakes
  • UDP traffic
  • DNS requests
  • HTTP traffic
  • TLS concepts
  • Source and destination addresses
  • Ports

Try capturing traffic generated by your own applications and understand what each packet represents.

Packet analysis is an excellent way to strengthen networking knowledge.


Stage 13: Learn Burp Suite

Burp Suite is widely used for web application security testing.

Start with:

  • Proxy
  • HTTP request/response inspection
  • Repeating requests
  • Modifying requests in a lab
  • Understanding cookies
  • Understanding authentication flows

Do not begin by trying to memorize every feature.

First understand:

Browser
   ↓
Burp Proxy
   ↓
Web Application
   ↓
Response
   ↓
Burp
   ↓
Browser

Once that flow is clear, the rest of the tool becomes easier to learn.


Stage 14: Study OWASP Web Security Testing

If web application security is your target, OWASP is one of the most useful learning resources available.

The current OWASP WSTG covers areas including:

  • Information gathering
  • Configuration testing
  • Identity management
  • Authentication testing
  • Authorization testing
  • Session management
  • Input validation
  • Error handling
  • Cryptography
  • Business logic

OWASP describes WSTG as a flexible methodology and technique reference rather than a rigid checklist. Its latest released version is currently 4.2, with 5.0 under development. (OWASP WSTG Introduction)


Stage 15: Learn Enumeration

Enumeration means gathering detailed information about identified systems and services.

Depending on the authorized target, you may study:

  • Service versions
  • Application technologies
  • Authentication mechanisms
  • Available endpoints
  • Network relationships
  • Security controls

The key is understanding what information is useful and why.


Stage 16: Learn Vulnerability Analysis

Once you understand a system, identify potential weaknesses.

Possible sources include:

  • Manual analysis
  • Automated scanners
  • Configuration reviews
  • Application behavior
  • Source-code review, when available
  • Known vulnerability information

Do not automatically treat scanner output as proof.

Always analyze the finding in context.


Stage 17: Learn Controlled Validation

A suspected vulnerability may need to be validated.

Validation should occur only when:

  • The target is in scope
  • The action is permitted
  • The potential impact is understood
  • The test is controlled
  • Sensitive data is protected

The purpose is to establish whether a suspected weakness actually produces the reported security impact.


Stage 18: Learn Penetration Testing Methodology

Tools are not a methodology.

One recognized reference described by OWASP is the Penetration Testing Execution Standard (PTES), which organizes penetration testing into seven phases:

  1. Pre-engagement Interactions
  2. Intelligence Gathering
  3. Threat Modeling
  4. Vulnerability Analysis
  5. Exploitation
  6. Post Exploitation
  7. Reporting

OWASP's methodology overview also references NIST SP 800-115, PCI penetration-testing guidance and other testing methodologies. (OWASP Penetration Testing Methodologies)

These phases should be adapted to the engagement rather than treated as a universal script.


Stage 19: Learn Pre-Engagement

This phase establishes the rules of the assessment.

Understand:

  • Scope
  • Objectives
  • Testing dates
  • Authorized systems
  • Excluded systems
  • Permitted methods
  • Prohibited methods
  • Emergency contacts
  • Reporting requirements

A professional penetration tester should be comfortable reading and following a scope document.


Stage 20: Learn Intelligence Gathering

Before deeper testing, understand the target.

This can include:

  • Domains
  • Subdomains
  • IP addresses
  • Technologies
  • Applications
  • Publicly available information

Always keep information gathering within the authorized scope.


Stage 21: Learn Threat Modeling

Threat modeling asks questions such as:

  • What are the important assets?
  • Who might attack them?
  • What attack paths could exist?
  • What security controls are present?
  • What happens if a control fails?

Threat modeling gives penetration testing context.


Stage 22: Learn Post-Exploitation Concepts

At an advanced level, security testers may need to understand what could happen after an initial compromise.

Study concepts such as:

  • Privilege boundaries
  • Credential exposure
  • Network segmentation
  • Lateral movement concepts
  • Persistence concepts
  • Detection opportunities

Practice these concepts only inside explicitly authorized labs.

The goal is to understand potential business impact and defensive controls, not to gain access to unrelated systems.


Stage 23: Learn Reporting

Reporting is one of the most important professional skills.

A good report may contain:

Executive Summary
Scope
Methodology
Limitations
Findings
Evidence
Risk
Impact
Recommendations
Retest Results
Appendices

A technical person should be able to reproduce the issue from the information provided, while management should be able to understand the business significance.


What Should a Penetration Testing Finding Contain?

A practical finding structure is:

Title
↓
Affected Asset
↓
Description
↓
Evidence
↓
Impact
↓
Risk Context
↓
Recommendation
↓
References
↓
Retest Status

For example:

Finding:
Insufficient Authorization

Affected Asset:
Authorized Test Application

Description:
A tested user role was able to access a resource
outside its intended permission boundary.

Impact:
The issue may expose information intended for
another role.

Recommendation:
Enforce server-side authorization checks for
every protected resource and action.

Retest:
Verify that the restricted request is denied.

Stage 24: Learn Vulnerability Prioritization

Not every vulnerability deserves the same remediation priority.

Consider:

  • Likelihood
  • Technical severity
  • Asset importance
  • Exposure
  • Exploitability
  • Business impact
  • Existing controls

This helps organizations decide where to spend limited remediation resources.


Stage 25: Build a Home Pentesting Lab

A lab is one of the best ways to learn penetration testing safely.

A basic setup could contain:

Host Computer
       |
   Virtualization
       |
+------+----------------+
|                       |
Tester VM            Target VM
|                       |
|                Vulnerable App
|                       |
+-----------+-----------+
            |
       Isolated Lab

You can install Linux and Windows virtual machines and connect deliberately vulnerable applications to a controlled network.


How Much Hardware Do You Need?

You do not need an expensive server to begin.

A basic computer that can run one or more virtual machines can be enough for many beginner exercises.

As you progress, more RAM and storage can make virtualization easier.

For resource-constrained learners, start small:

  • One Linux VM
  • One target VM
  • One isolated network

You can expand the lab later.


Stage 26: Build Projects

Projects turn knowledge into evidence.

Beginner Projects

  • Local network inventory tool
  • Python log analyzer
  • File integrity monitor
  • Security headers checker
  • Hashing demonstration application
  • Linux security checklist

Intermediate Projects

  • Mini vulnerability-management dashboard
  • Web security testing report
  • Security log monitoring system
  • Network monitoring dashboard
  • Authentication monitoring tool
  • Cloud configuration checker

Stage 27: Build Your Portfolio

A strong penetration-testing portfolio can include:

  • GitHub projects
  • Lab documentation
  • Security reports
  • Web-security write-ups
  • CTF write-ups from permitted environments
  • Python security scripts
  • Network-analysis projects
  • Remediation examples

For each project, use a consistent structure:

Problem
Scope
Environment
Approach
Tools
Findings
Impact
Remediation
Retest
Lessons Learned

Stage 28: Choose a Specialization

Penetration testing is broad.

Eventually, choose an area to explore deeply.

Web Application Security

Focus on applications, APIs, authentication, authorization, sessions and business logic.

Network Penetration Testing

Focus on network services, segmentation, protocols and infrastructure.

Active Directory

Focus on Windows enterprise environments, identity and access relationships.

Cloud Security

Focus on cloud identities, permissions, configurations and exposed resources.

Mobile Security

Focus on mobile applications and backend communication.

Red Teaming

Focus on broader adversary simulation within carefully defined rules of engagement.


Web Pentesting Roadmap

HTTP
 ↓
HTML / JavaScript
 ↓
Cookies / Sessions
 ↓
Authentication
 ↓
Authorization
 ↓
APIs
 ↓
SQL / Databases
 ↓
OWASP
 ↓
Burp Suite
 ↓
Web Security Labs
 ↓
Reporting

OWASP's Web Security Testing Guide is particularly useful for this path. The project currently lists WSTG 4.2 as its latest released version while 5.0 is being developed. (OWASP WSTG)


Network Pentesting Roadmap

Networking
 ↓
TCP / UDP
 ↓
Ports
 ↓
Services
 ↓
Nmap
 ↓
Wireshark
 ↓
Enumeration
 ↓
Firewall Concepts
 ↓
Network Security
 ↓
Controlled Validation
 ↓
Reporting

Active Directory Learning Roadmap

Windows Fundamentals
 ↓
Users & Groups
 ↓
Domains
 ↓
Active Directory
 ↓
Kerberos Concepts
 ↓
LDAP Concepts
 ↓
Group Policies
 ↓
Permissions
 ↓
Enterprise Security
 ↓
Authorized AD Lab
 ↓
Reporting

Do not begin with advanced Active Directory attack techniques before understanding Windows and identity fundamentals.


Cloud Pentesting Roadmap

Cloud Fundamentals
 ↓
IAM
 ↓
Networking
 ↓
Storage
 ↓
Compute
 ↓
Logging
 ↓
Secrets
 ↓
Configuration
 ↓
Cloud Security Testing
 ↓
Reporting

Cloud testing requires additional attention to the provider's security-testing policies and the organization's authorization.


Certifications and Penetration Testing

Certifications can provide structure and may help demonstrate certain knowledge or hands-on capabilities.

Before selecting one, compare:

  • Current syllabus
  • Exam format
  • Practical requirements
  • Prerequisites
  • Cost
  • Renewal requirements
  • Relationship to your target role

Do not choose a certification simply because somebody says it is "the best."

First identify the skills you need.


Skills vs Certifications

Skill Evidence Certification Evidence
ProjectsExam result
Lab reportsCredential
GitHub repositoriesCertification body
Practical demonstrationsStructured learning path
Security write-upsFormal assessment

For a strong profile, skills and documented practice should support any certifications you earn.


A 12-Month Penetration Testing Study Plan

Month Focus
1Computer fundamentals
2Networking fundamentals
3Linux
4Windows + PowerShell
5Python + SQL
6HTTP + Web Technologies
7Security fundamentals
8Nmap + Wireshark
9Web security + Burp Suite
10Hands-on labs
11Specialization + projects
12Reporting + portfolio + interview preparation

This is a flexible example. Your progress depends on your existing knowledge, available study time and amount of hands-on practice.


A Daily Penetration Testing Study Routine

A balanced routine could look like:

30 min → Theory
30 min → Networking / Linux
60 min → Hands-on Lab
30 min → Notes
30 min → Project

On busy days, even one focused practical session can be useful.


How to Practice Efficiently

Do not spend all your time watching tutorials.

Use a cycle such as:

Learn
 ↓
Practice
 ↓
Break
 ↓
Understand
 ↓
Fix
 ↓
Document
 ↓
Repeat

The "document" step is often ignored, but it becomes valuable when building a professional portfolio.


How to Take Notes

Create separate notes for:

  • Networking
  • Linux
  • Windows
  • Web security
  • Nmap
  • Wireshark
  • Burp Suite
  • OWASP
  • Labs
  • Reporting

For every new concept, write:

What is it?
Why does it matter?
How does it work?
How can I detect it?
How can it be fixed?

How to Measure Your Progress

Do not measure your progress only by the number of tools installed.

Instead, ask whether you can:

  • Explain how a network works
  • Interpret Nmap results
  • Read HTTP requests
  • Understand authentication
  • Identify an authorization problem in a lab
  • Analyze logs
  • Write a Python automation script
  • Explain the impact of a finding
  • Recommend a remediation
  • Write a professional report

Common Beginner Mistakes

1. Starting With Advanced Exploitation

Build fundamentals first.

2. Ignoring Networking

Network knowledge is foundational.

3. Learning Only Kali Linux

Kali is an environment, not a substitute for understanding Linux and security.

4. Memorizing Commands

Understand why and when to use a command.

5. Using Automated Scanners Without Verification

Scanner results can require manual validation.

6. Ignoring Reporting

Professional security work requires clear communication.

7. Practicing on Unauthorized Targets

This can create legal, contractual and operational problems.

8. Collecting Certifications Without Practical Work

Build real technical evidence alongside any certifications.


What Should You Avoid Learning First?

You do not need to begin with:

  • Advanced exploit development
  • Complex malware analysis
  • Advanced reverse engineering
  • Highly specialized hardware attacks
  • Complex red-team infrastructure

These topics can come later.

Build a strong foundation first.


How to Build a Professional Pentesting Mindset

Instead of asking:

"Which exploit should I run?"

learn to ask:

"What is the system supposed to do, what security control protects it, and can I demonstrate a weakness within the authorized scope?"

This mindset encourages analysis before action.


Penetration Testing and Secure Development

Application security should not depend only on penetration testing after an application has been built.

OWASP's current testing framework emphasizes considering security throughout the software lifecycle, including definition, design, development, deployment, maintenance and operations. (OWASP Testing Framework)

A broader secure-development process can look like:

Requirements
 ↓
Threat Modeling
 ↓
Secure Design
 ↓
Secure Coding
 ↓
Code Review
 ↓
Security Testing
 ↓
Deployment
 ↓
Monitoring
 ↓
Penetration Testing
 ↓
Improvement

Penetration testing is therefore one part of a larger security program.


How a Penetration Tester Should Think About a Finding

A useful mental model is:

Weakness
   ↓
Can It Be Validated?
   ↓
What Access Does It Provide?
   ↓
What Resource Is Affected?
   ↓
What Is The Security Impact?
   ↓
How Should It Be Fixed?

This turns technical observations into actionable security findings.


Penetration Testing Portfolio Checklist

  • □ Linux lab
  • □ Windows lab
  • □ Networking project
  • □ Nmap project
  • □ Wireshark analysis
  • □ Web-security lab
  • □ Burp Suite exercise
  • □ Python automation project
  • □ Vulnerability report
  • □ Remediation example
  • □ GitHub repository
  • □ Technical write-up

Frequently Asked Questions

1. What should I learn first for penetration testing?

Start with computer fundamentals, networking, Linux and Windows basics. Then add programming, web technologies and security fundamentals.

2. Is Kali Linux enough to become a penetration tester?

No. Kali Linux provides a useful security-testing environment, but it does not replace networking, Linux, Windows, programming, web-security knowledge and hands-on practice.

3. Is networking important for penetration testing?

Yes. Networking is one of the most important foundations for understanding ports, services, protocols, firewalls and network behavior.

4. Do I need programming for penetration testing?

You do not need advanced programming immediately, but Python, Bash, PowerShell, SQL and JavaScript can become very useful as your skills develop.

5. Which programming language should I learn first?

Python is a practical starting point because it is useful for automation, scripting, APIs and data processing.

6. Should I learn web security?

Yes, especially if you are interested in websites and APIs. HTTP, authentication, authorization, sessions, databases and application architecture are important foundations.

7. Is Nmap enough for penetration testing?

No. Nmap is useful for discovery and service identification, but a penetration test requires planning, analysis, validation, reporting and remediation.

8. What is the difference between vulnerability assessment and penetration testing?

Vulnerability assessment generally focuses on finding potential weaknesses, while penetration testing can include controlled validation of selected weaknesses and their security impact.

9. Can I practice penetration testing on public websites?

Do not assume that public availability means authorization. Use your own systems, training platforms, deliberately vulnerable labs or systems where you have explicit permission.

10. How long does it take to learn penetration testing?

There is no universal timeline. Progress depends on your current technical knowledge, study time, hands-on practice and chosen specialization.

11. Do I need certifications?

Certification requirements vary by role and employer. Certifications can be useful, but they should complement practical knowledge and project experience.

12. Is reporting really important?

Yes. A professional tester needs to communicate findings, impact and remediation clearly. Technical testing without useful documentation has limited value to the organization.

13. What is the PTES methodology?

The Penetration Testing Execution Standard organizes penetration testing into seven phases: pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post exploitation and reporting. OWASP references PTES in its penetration-testing methodology guidance. (OWASP PTES Reference)

14. What is OWASP WSTG?

The OWASP Web Security Testing Guide is a practical reference for testing web applications and web services. The project currently lists version 4.2 as the latest released version while version 5.0 is under development. (OWASP WSTG)


Final Thoughts

Penetration testing is not something you learn by installing a security distribution and memorizing commands.

A stronger roadmap is:

Computers → Networking → Linux → Windows → Programming → Web → Security → Tools → Labs → Methodology → Reporting → Specialization

Build each layer before moving heavily into the next one.

NIST's technical security-testing guidance emphasizes planning, execution and evaluation, while OWASP's current testing resources emphasize adaptable methodologies, risk-based prioritization and a combination of automated and manual techniques. (NIST SP 800-115)

The biggest mistake beginners make is focusing on how to attack before understanding how the system works.

Reverse that order.

Learn the technology first, practice safely, document your findings, understand remediation and gradually specialize.

That gives you a much more useful foundation for a long-term penetration-testing career.

Remember: Authorization is part of the technical process, not an optional detail. Always know exactly what you are allowed to test before performing security testing.

Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the related CodeWithAV articles after publication.


Official Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.

Nmap Tutorial for Beginners: Complete Guide to Network Scanning

Nmap Tutorial for Beginners: Complete Guide to Network Scanning

When you start learning cybersecurity, one of the first tools you are likely to encounter is Nmap.

Nmap is commonly used for network discovery, port scanning, service identification and security auditing. It is useful to administrators, security professionals, penetration testers and students learning networking.

But many beginners make the mistake of learning Nmap by memorizing commands without understanding what those commands actually do.

This tutorial takes a different approach.

We will first understand:

  • What Nmap is
  • What a port is
  • What Nmap actually scans
  • How port states work
  • How host discovery works
  • How to perform basic scans
  • How to identify services
  • How to interpret Nmap output
  • How to save scan results
  • How to build a safe Nmap practice lab

Important: Only scan systems and networks that you own or have explicit permission to test. The Nmap Project itself recommends obtaining authorization before scanning a network. It also provides scanme.nmap.org as an authorized practice target specifically for Nmap scans, with restrictions described in its legal guidance. Do not use that authorization for exploitation or denial-of-service testing. (Official Nmap Legal Guidance)


What Is Nmap?

Nmap stands for Network Mapper.

According to the official Nmap documentation, it is a free and open-source tool for network exploration and security auditing. It can determine information such as available hosts, services and versions, operating-system characteristics and packet-filtering behavior. (Official Nmap Introduction)

A simplified example is:

Your Computer
      |
      | Nmap
      ↓
Target System
      |
      ├── Is the host reachable?
      ├── Which ports are open?
      ├── What services are running?
      └── What information can be identified?

Nmap is therefore much more than a simple "port scanner."


Why Is Nmap Important in Cybersecurity?

Before securing a network, you need to understand what is exposed.

For example, imagine a server has these ports available:

22/tcp   SSH
80/tcp   HTTP
443/tcp  HTTPS
3306/tcp MySQL

That immediately gives an administrator useful information about the services that may need to be reviewed.

Security professionals can use authorized scanning to help answer questions such as:

  • Which hosts are active?
  • Which ports are reachable?
  • Which services appear to be running?
  • Which service versions are visible?
  • Which systems have unexpected exposure?

The official Nmap guide describes network inventory, security auditing and service discovery among its practical uses. (Nmap Network Scanning)


What Is a Port?

Before using Nmap, you need to understand ports.

A networked computer can run multiple services. Ports provide a way for network traffic to be associated with those services.

Some commonly known ports include:

Port Common Service
22SSH
25SMTP
53DNS
80HTTP
110POP3
143IMAP
443HTTPS
3306MySQL
5432PostgreSQL
6379Redis

A port number alone does not guarantee which service is actually running there. Services can be configured to use non-standard ports.

Nmap's service and version detection features are designed to identify what is actually listening rather than relying only on a port-number assumption. (Nmap Service and Version Detection)


Nmap Installation

Nmap runs on major desktop operating systems, including Linux, Windows and macOS. (Nmap Official Guide)

Ubuntu / Debian

sudo apt update
sudo apt install nmap

Fedora-Based Systems

sudo dnf install nmap

Arch Linux

sudo pacman -S nmap

Windows

Download Nmap from the official Nmap website rather than an unofficial software mirror.

Official Nmap Download Page

After installation, verify it:

nmap --version

You should see the installed Nmap version and related information.


Basic Nmap Syntax

The general structure is:

nmap [options] target

For example:

nmap 192.168.1.10

Here:

  • nmap = program
  • 192.168.1.10 = target

Options modify how Nmap performs the scan.


Start With Your Own Computer

The safest way for a beginner to start is to scan the local system.

Try:

nmap localhost

You can also use:

nmap 127.0.0.1

These refer to the local host in common configurations.

This lets you experiment without scanning someone else's machine.


Understanding Nmap Output

A basic scan might produce output resembling:

Starting Nmap

PORT    STATE    SERVICE
22/tcp  open     ssh
80/tcp  open     http
443/tcp open     https

Nmap done

The important columns are:

Column Meaning
PORTPort number and protocol
STATEObserved state of the port
SERVICEProbable service associated with the port

Nmap Port States

Nmap reports several different port states.

1. Open

An open port means an application is listening and accepting connections or packets associated with that port.

2. Closed

A closed port is reachable, but no application is listening on it at the time of the scan.

3. Filtered

A filtered port means Nmap cannot determine whether it is open because packet filtering prevents it from determining the state.

4. Unfiltered

Unfiltered means the port is accessible but Nmap cannot determine from the scan whether it is open or closed for that particular scan method.

5. Open|Filtered

Nmap may use open|filtered when it cannot determine whether the port is open or filtered.

6. Closed|Filtered

Some scan types can also produce closed|filtered where the distinction cannot be determined.

Understanding these states is much more important than simply looking for the word "open."


Basic Scan

The simplest Nmap scan is:

nmap 127.0.0.1

Nmap performs a basic scan of the target and reports discovered ports.

Use this first to become familiar with the output.


Scan a Specific Port

You can specify a particular port:

nmap -p 80 127.0.0.1

To scan another port:

nmap -p 443 127.0.0.1

This is useful when you already know which service you want to check.


Scan Multiple Ports

You can specify several ports separated by commas:

nmap -p 22,80,443 127.0.0.1

You can also specify a range:

nmap -p 20-100 127.0.0.1

For lab environments, port ranges are useful for understanding how exposed services appear in a scan.


Scan All TCP Ports

Nmap's common default scan does not examine every possible TCP port.

You can request all TCP ports with:

nmap -p- 127.0.0.1

This scans TCP ports 1 through 65535.

Use broad scans primarily in systems you own or authorized lab environments because they generate more traffic and can take longer.


Scan a Network Range

Nmap can also work with multiple targets.

For example, in your own home lab:

nmap 192.168.1.0/24

This represents a CIDR network range.

Before scanning a network range, verify that the entire range belongs to your network or that you have authorization to assess it.


Host Discovery

Sometimes you first want to know which systems are reachable.

Nmap provides host-discovery capabilities.

A common example is:

nmap -sn 192.168.1.0/24

The -sn option performs host discovery without a port scan.

This can be useful for inventorying systems in an authorized network.


Why Host Discovery Matters

Imagine a lab network containing:

192.168.1.10 → Linux Server
192.168.1.11 → Windows VM
192.168.1.12 → Web Server
192.168.1.13 → Database VM

A host-discovery scan can help you identify systems that respond to the discovery methods being used.

Remember that network controls can cause some hosts not to respond to particular discovery probes.


Service and Version Detection

Finding an open port is only the beginning.

Suppose Nmap reports:

80/tcp open http

You may want to know what web server is actually running.

Use:

nmap -sV 127.0.0.1

The -sV option enables service/version detection.

According to the official documentation, Nmap uses service probes to identify services and, where possible, application names and version information. (Official Service and Version Detection Guide)

Example output may look like:

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH
80/tcp open  http    Apache

The exact results depend on the target.


Why Version Detection Is Useful

Imagine finding:

80/tcp open http

That tells you a web service is available.

But:

80/tcp open http Apache

gives you additional information about the service.

Version information can help administrators identify outdated software and determine which systems require maintenance or security review.


Operating System Detection

Nmap can attempt operating-system detection with:

sudo nmap -O 127.0.0.1

The -O option enables OS detection.

Nmap attempts to infer characteristics of the target operating system from responses to its probes.

OS detection may not always identify the system perfectly. Network filtering, virtualization and other factors can affect the results.


Aggressive Detection

Nmap also provides the -A option.

nmap -A 127.0.0.1

According to Nmap's documentation, -A enables several advanced detection features, including OS detection, version detection, script scanning and traceroute-related functionality. (Nmap Reference Guide)

Because this performs more checks, it is best used in your own lab or an explicitly authorized environment.


Nmap Default Scripts

Nmap includes the Nmap Scripting Engine (NSE).

NSE allows scripts to extend Nmap's capabilities for tasks such as service discovery, security checks and information gathering.

A common command is:

nmap -sC 127.0.0.1

The -sC option runs the default category of NSE scripts.

Use scripting only where you are authorized to perform the corresponding checks.

The official Nmap reference guide documents NSE as a major part of the tool's capabilities. (Nmap Reference Guide)


TCP SYN Scan

One of Nmap's well-known scanning methods is the TCP SYN scan:

sudo nmap -sS 127.0.0.1

The -sS option performs a TCP SYN scan.

At a conceptual level, Nmap uses TCP behavior to infer whether ports are open, closed or filtered.

You do not need to understand the packet-level details immediately. First learn how to interpret the resulting port states.


TCP Connect Scan

Nmap can also perform a TCP connect scan:

nmap -sT 127.0.0.1

The -sT method uses the operating system's normal connection mechanism.

The actual scanning method available or selected can depend on privileges and operating-system behavior.


UDP Scanning

Nmap can also scan UDP ports.

sudo nmap -sU 127.0.0.1

UDP scanning can be slower and can produce states such as open|filtered because UDP does not use the same connection process as TCP.

Only perform UDP scans against systems that you are authorized to assess.


Scan a Specific UDP Port

sudo nmap -sU -p 53 127.0.0.1

This is useful when testing a service in your own lab.


Fast Scan

Nmap provides a fast-scan option:

nmap -F 127.0.0.1

The -F option reduces the set of ports scanned compared with broader scans.

This is useful when you want a quick initial check.


Increase Scan Speed

Nmap provides timing templates such as:

nmap -T4 127.0.0.1

The timing templates range from slower and more cautious behavior to faster scanning.

Faster does not always mean better.

Increasing scan speed can affect accuracy, network load and the way network defenses respond.

Use aggressive timing carefully and primarily in controlled environments.


Disable Host Discovery

Sometimes you already know a target is online and want Nmap to skip host discovery.

nmap -Pn 192.168.1.10

The -Pn option treats the host as online instead of relying on host-discovery checks to decide whether to scan it.

This can be useful when discovery traffic is filtered.


Scan Only Selected TCP Ports

You can specify a list:

nmap -p 22,80,443 127.0.0.1

Or a range:

nmap -p 1-1024 127.0.0.1

This is a good way to practice without immediately scanning every port.


Scan Top Ports

Nmap also supports selecting a number of commonly used ports:

nmap --top-ports 20 127.0.0.1

You can change the number according to the needs of your authorized lab test.


Verbose Mode

Verbose mode provides more information while the scan is running.

nmap -v 127.0.0.1

For even more output, Nmap supports higher verbosity levels:

nmap -vv 127.0.0.1

This can help beginners understand what the tool is doing.


Save Nmap Results to a File

Saving scan results is important for documentation and comparison.

Normal Output

nmap -oN scan.txt 127.0.0.1

XML Output

nmap -oX scan.xml 127.0.0.1

Grepable Output

nmap -oG scan.gnmap 127.0.0.1

All Major Output Formats

nmap -oA myscan 127.0.0.1

The -oA option saves output in multiple formats using the specified base filename.


Why Save Scan Results?

Imagine you scan your own lab today:

22/tcp open ssh
80/tcp open http

After you change the server configuration, you scan again:

80/tcp open http

You can compare the two reports and confirm that SSH is no longer exposed.

This makes Nmap useful for network inventory and security validation, not just one-time experiments.


Scanning Multiple Hosts

You can specify multiple IP addresses:

nmap 192.168.1.10 192.168.1.11 192.168.1.12

You can also use a host range in an authorized environment:

nmap 192.168.1.10-20

Always verify that the targets are part of your authorized scope.


Scan a Domain You Are Authorized to Test

Nmap can accept hostnames:

nmap example.com

However, the fact that a website is publicly accessible does not mean that you have permission to scan it.

For learning, your safest options are:

  • Your own computer
  • Your own server
  • Your own home lab
  • Virtual machines
  • Dedicated security-training targets
  • Targets explicitly authorized for scanning

The Official scanme.nmap.org Practice Target

The Nmap Project provides scanme.nmap.org as a special target for practicing Nmap.

The official legal guide says this authorization is for Nmap scanning and does not extend to exploit testing or denial-of-service attacks. It also asks users not to initiate more than a dozen scans against the host per day to conserve bandwidth. (Nmap Legal Issues)

A basic authorized example is:

nmap scanme.nmap.org

Keep your practice limited to the permission provided by the Nmap Project.


A Beginner Nmap Workflow

Instead of randomly trying commands, follow a logical process.

1. Identify authorized target
            ↓
2. Check host availability
            ↓
3. Perform basic port scan
            ↓
4. Identify open ports
            ↓
5. Detect services
            ↓
6. Investigate configuration
            ↓
7. Document findings
            ↓
8. Fix unnecessary exposure
            ↓
9. Scan again

This workflow is much closer to how network assessment becomes useful in practice.


Example: Building a Small Local Lab

Suppose you have one Linux machine running locally.

First find your local addresses:

ip addr

Then check listening services:

ss -tuln

Now compare the operating system's local information with Nmap:

nmap 127.0.0.1

Then try service detection:

nmap -sV 127.0.0.1

This gives you a simple exercise:

Can you explain why each port reported by Nmap is open and which local service is responsible for it?

Nmap and ss: Why Use Both?

ss shows local socket information from the system.

Nmap approaches the target from the network perspective.

This distinction is valuable.

Tool Perspective
ss Local system
Nmap Network view of the target

Comparing both can help you understand firewall behavior and network exposure.


Nmap vs Netstat

Older Linux tutorials often introduce netstat.

Modern Linux systems frequently use ss instead.

Nmap serves a different purpose because it is designed for network discovery and scanning rather than simply displaying local socket information.


Nmap vs Ping

These tools answer different questions.

Ping:

ping 192.168.1.10

Primarily tests basic IP-level reachability using ICMP echo behavior when permitted.

Nmap:

nmap 192.168.1.10

Can investigate ports, services and other network characteristics.

A host can be reachable while not responding to ping, because network controls may filter ICMP.


Common Nmap Options Cheat Sheet

Option Purpose
-snHost discovery without a port scan
-sSTCP SYN scan
-sTTCP connect scan
-sUUDP scan
-sVService/version detection
-OOS detection
-ASeveral advanced detection features
-sCDefault NSE scripts
-pSpecify ports
-p-Scan all TCP ports
-FFast scan
-PnSkip host discovery assumption
-vVerbose output
-oNNormal output file
-oXXML output
-oGGrepable output
-oASave multiple output formats
--top-portsScan selected common ports
-T4Use a faster timing template

Useful Beginner Commands

Basic Scan

nmap 127.0.0.1

Specific Ports

nmap -p 22,80,443 127.0.0.1

Service Detection

nmap -sV 127.0.0.1

OS Detection

sudo nmap -O 127.0.0.1

Default Scripts

nmap -sC 127.0.0.1

All TCP Ports

nmap -p- 127.0.0.1

Save Results

nmap -oA lab-scan 127.0.0.1

How to Read an Nmap Scan Like a Beginner

Suppose you receive:

PORT     STATE  SERVICE
22/tcp   open   ssh
80/tcp   open   http
443/tcp  open   https
8080/tcp open   http-proxy

Do not immediately think:

"I found four vulnerabilities."

You have not.

You have found four network services that appear accessible.

The next questions should be:

  • Are these services expected?
  • Who needs them?
  • Are they securely configured?
  • Are the versions current?
  • Should any service be restricted?
  • Is the exposure intentional?

This is the difference between scanning and security analysis.


Nmap Does Not Automatically Mean Vulnerability

This is an important concept.

An open port is not automatically a vulnerability.

For example:

443/tcp open https

This may simply mean the server intentionally provides a secure web service.

The security question is whether the service is appropriately configured, maintained and exposed.


Common Beginner Mistakes With Nmap

1. Scanning Random Public IP Addresses

Do not assume that a publicly reachable system is available for testing.

2. Using Aggressive Options Immediately

Start with simple scans and learn how to interpret the results.

3. Treating Every Open Port as a Vulnerability

Open services can be completely legitimate.

4. Ignoring Scope

In professional security assessments, scan only the systems and address ranges included in the authorized scope.

5. Focusing on Commands Instead of Networking

Understanding TCP, UDP, IP addresses, ports, routing and firewalls makes Nmap much easier to understand.

6. Not Saving Results

Always document significant authorized assessments.

7. Ignoring False Positives and Limitations

Nmap makes inferences from network responses. Detection results are not perfect and should be interpreted carefully.


Nmap and Firewalls

Firewalls can affect scan results.

For example, a firewall may:

  • Allow traffic
  • Reject traffic
  • Drop traffic silently
  • Allow only certain source addresses
  • Allow only particular ports

This can produce different Nmap states.

For example:

Port A → open
Port B → closed
Port C → filtered

Understanding why the results differ requires networking knowledge.


How Nmap Fits Into a Security Assessment

A simplified authorized security workflow may look like:

Scope
  ↓
Asset Discovery
  ↓
Port Scanning
  ↓
Service Identification
  ↓
Configuration Review
  ↓
Vulnerability Assessment
  ↓
Risk Analysis
  ↓
Remediation
  ↓
Verification
  ↓
Report

Nmap is mainly useful during discovery and service-identification stages, though its other capabilities can support additional assessment tasks.


Mini Nmap Lab for Beginners

Try this sequence on your own machine.

Step 1 — Check Local Services

ss -tuln

Step 2 — Perform Basic Nmap Scan

nmap 127.0.0.1

Step 3 — Scan Common Ports

nmap --top-ports 20 127.0.0.1

Step 4 — Detect Services

nmap -sV 127.0.0.1

Step 5 — Scan All TCP Ports

nmap -p- 127.0.0.1

Step 6 — Save Results

nmap -oA first-lab-scan 127.0.0.1

Step 7 — Document What You Learned

Write down:

  • Which ports were open?
  • Which services were identified?
  • Which ports did you expect?
  • Were any unexpected services visible?
  • What configuration changes could reduce unnecessary exposure?

Beginner Nmap Learning Roadmap

Networking Fundamentals
       ↓
TCP / UDP
       ↓
Ports and Services
       ↓
Basic Nmap
       ↓
Host Discovery
       ↓
Port States
       ↓
Service Detection
       ↓
OS Detection
       ↓
NSE
       ↓
Output and Reporting
       ↓
Authorized Security Labs

What Should You Learn Before Nmap?

For better results, learn these concepts first:

  • IP addresses
  • TCP and UDP
  • Ports
  • DNS
  • Routing
  • Firewalls
  • Network interfaces
  • Basic Linux commands

Our earlier CodeWithAV articles on networking and Linux can help build this foundation.


What Should You Learn After Nmap?

Once you understand basic Nmap, continue with:

  • Wireshark
  • Web application security
  • Burp Suite
  • OWASP fundamentals
  • Vulnerability management
  • Security logging
  • Network defense
  • Penetration-testing methodology

The goal should be to understand why a result matters, not just how to produce it.


Frequently Asked Questions

1. Is Nmap a hacking tool?

Nmap is a network exploration and security-auditing tool. It is used by administrators and security professionals for legitimate network discovery, inventory and testing. Whether its use is appropriate depends on authorization and how it is used.

2. Is Nmap free?

Yes. Nmap is free and open-source software. The official Nmap site provides downloads and documentation. (Nmap Official Website)

3. Is Nmap legal?

The legality of scanning depends on the jurisdiction, circumstances and authorization involved. The Nmap Project recommends securing written authorization before scanning networks and explains that users should understand applicable rules and provider policies. (Nmap Legal Guidance)

4. Can I scan my own computer?

Yes. Scanning systems you own or are explicitly authorized to test is the appropriate way to practice.

5. What does an open port mean?

An open port indicates that Nmap has determined that an application is listening and accepting relevant network communication on that port.

6. Does an open port mean the system is vulnerable?

No. An open port simply indicates an accessible service. You need additional analysis to determine whether a service is unnecessarily exposed, outdated or insecurely configured.

7. What is the difference between -sS and -sT?

-sS performs a TCP SYN scan, while -sT performs a TCP connect scan. The exact behavior and privilege requirements depend on the operating system and environment.

8. What is -sV?

-sV enables service and version detection, allowing Nmap to probe discovered services and attempt to identify the application and version.

9. What is -O?

-O enables operating-system detection. Nmap attempts to infer the target's operating-system characteristics from network responses.

10. What is NSE?

NSE stands for Nmap Scripting Engine. It allows scripts to extend Nmap for additional discovery, information gathering and security-related checks.

11. What is the safest Nmap target for beginners?

Your own computer or a deliberately created virtual-machine lab is the safest starting point. The Nmap Project also provides scanme.nmap.org as an explicitly authorized Nmap practice target with usage restrictions. (Official Scanme Guidance)

12. Can Nmap crash a server?

Most ordinary scans are designed for network discovery and auditing, but unexpected behavior or fragile systems can create problems. The safest approach is to scan authorized systems and begin with conservative tests.


Final Thoughts

Nmap is one of the most useful tools for learning the relationship between networking and cybersecurity.

But learning Nmap is not about memorizing hundreds of commands.

Start with a few fundamental concepts:

Host → Port → Service → Version → Configuration → Risk → Remediation

Practice first on 127.0.0.1, your own virtual machines and authorized training environments.

Once you understand what Nmap is actually telling you, commands such as -sV, -O, -p, -sn and -oA become much easier to understand.

Most importantly, remember that network visibility is not the same thing as vulnerability.

A professional security mindset asks:

What is exposed, why is it exposed, is that exposure necessary, and how can it be secured?

That is the mindset worth developing as you continue your cybersecurity journey.


Recommended Reading on CodeWithAV

Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV posts after publication.


Official Nmap Resources

Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.

Adarsh verma

Adarsh verma

CodeWithAV publishes practical technology tutorials, study resources, programming guides, and cybersecurity learning content.