Nmap Tutorial for Beginners: Complete Guide to Network Scanning
When you start learning cybersecurity, one of the first tools you are likely to encounter is Nmap.
Nmap is commonly used for network discovery, port scanning, service identification and security auditing. It is useful to administrators, security professionals, penetration testers and students learning networking.
But many beginners make the mistake of learning Nmap by memorizing commands without understanding what those commands actually do.
This tutorial takes a different approach.
We will first understand:
- What Nmap is
- What a port is
- What Nmap actually scans
- How port states work
- How host discovery works
- How to perform basic scans
- How to identify services
- How to interpret Nmap output
- How to save scan results
- How to build a safe Nmap practice lab
Important: Only scan systems and networks that you own or have explicit permission to test. The Nmap Project itself recommends obtaining authorization before scanning a network. It also provides scanme.nmap.org as an authorized practice target specifically for Nmap scans, with restrictions described in its legal guidance. Do not use that authorization for exploitation or denial-of-service testing. (Official Nmap Legal Guidance)
What Is Nmap?
Nmap stands for Network Mapper.
According to the official Nmap documentation, it is a free and open-source tool for network exploration and security auditing. It can determine information such as available hosts, services and versions, operating-system characteristics and packet-filtering behavior. (Official Nmap Introduction)
A simplified example is:
Your Computer
|
| Nmap
↓
Target System
|
├── Is the host reachable?
├── Which ports are open?
├── What services are running?
└── What information can be identified?
Nmap is therefore much more than a simple "port scanner."
Why Is Nmap Important in Cybersecurity?
Before securing a network, you need to understand what is exposed.
For example, imagine a server has these ports available:
22/tcp SSH 80/tcp HTTP 443/tcp HTTPS 3306/tcp MySQL
That immediately gives an administrator useful information about the services that may need to be reviewed.
Security professionals can use authorized scanning to help answer questions such as:
- Which hosts are active?
- Which ports are reachable?
- Which services appear to be running?
- Which service versions are visible?
- Which systems have unexpected exposure?
The official Nmap guide describes network inventory, security auditing and service discovery among its practical uses. (Nmap Network Scanning)
What Is a Port?
Before using Nmap, you need to understand ports.
A networked computer can run multiple services. Ports provide a way for network traffic to be associated with those services.
Some commonly known ports include:
| Port | Common Service |
|---|---|
| 22 | SSH |
| 25 | SMTP |
| 53 | DNS |
| 80 | HTTP |
| 110 | POP3 |
| 143 | IMAP |
| 443 | HTTPS |
| 3306 | MySQL |
| 5432 | PostgreSQL |
| 6379 | Redis |
A port number alone does not guarantee which service is actually running there. Services can be configured to use non-standard ports.
Nmap's service and version detection features are designed to identify what is actually listening rather than relying only on a port-number assumption. (Nmap Service and Version Detection)
Nmap Installation
Nmap runs on major desktop operating systems, including Linux, Windows and macOS. (Nmap Official Guide)
Ubuntu / Debian
sudo apt update sudo apt install nmap
Fedora-Based Systems
sudo dnf install nmap
Arch Linux
sudo pacman -S nmap
Windows
Download Nmap from the official Nmap website rather than an unofficial software mirror.
After installation, verify it:
nmap --version
You should see the installed Nmap version and related information.
Basic Nmap Syntax
The general structure is:
nmap [options] target
For example:
nmap 192.168.1.10
Here:
- nmap = program
- 192.168.1.10 = target
Options modify how Nmap performs the scan.
Start With Your Own Computer
The safest way for a beginner to start is to scan the local system.
Try:
nmap localhost
You can also use:
nmap 127.0.0.1
These refer to the local host in common configurations.
This lets you experiment without scanning someone else's machine.
Understanding Nmap Output
A basic scan might produce output resembling:
Starting Nmap PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https Nmap done
The important columns are:
| Column | Meaning |
|---|---|
| PORT | Port number and protocol |
| STATE | Observed state of the port |
| SERVICE | Probable service associated with the port |
Nmap Port States
Nmap reports several different port states.
1. Open
An open port means an application is listening and accepting connections or packets associated with that port.
2. Closed
A closed port is reachable, but no application is listening on it at the time of the scan.
3. Filtered
A filtered port means Nmap cannot determine whether it is open because packet filtering prevents it from determining the state.
4. Unfiltered
Unfiltered means the port is accessible but Nmap cannot determine from the scan whether it is open or closed for that particular scan method.
5. Open|Filtered
Nmap may use open|filtered when it cannot determine whether the port is open or filtered.
6. Closed|Filtered
Some scan types can also produce closed|filtered where the distinction cannot be determined.
Understanding these states is much more important than simply looking for the word "open."
Basic Scan
The simplest Nmap scan is:
nmap 127.0.0.1
Nmap performs a basic scan of the target and reports discovered ports.
Use this first to become familiar with the output.
Scan a Specific Port
You can specify a particular port:
nmap -p 80 127.0.0.1
To scan another port:
nmap -p 443 127.0.0.1
This is useful when you already know which service you want to check.
Scan Multiple Ports
You can specify several ports separated by commas:
nmap -p 22,80,443 127.0.0.1
You can also specify a range:
nmap -p 20-100 127.0.0.1
For lab environments, port ranges are useful for understanding how exposed services appear in a scan.
Scan All TCP Ports
Nmap's common default scan does not examine every possible TCP port.
You can request all TCP ports with:
nmap -p- 127.0.0.1
This scans TCP ports 1 through 65535.
Use broad scans primarily in systems you own or authorized lab environments because they generate more traffic and can take longer.
Scan a Network Range
Nmap can also work with multiple targets.
For example, in your own home lab:
nmap 192.168.1.0/24
This represents a CIDR network range.
Before scanning a network range, verify that the entire range belongs to your network or that you have authorization to assess it.
Host Discovery
Sometimes you first want to know which systems are reachable.
Nmap provides host-discovery capabilities.
A common example is:
nmap -sn 192.168.1.0/24
The -sn option performs host discovery without a port scan.
This can be useful for inventorying systems in an authorized network.
Why Host Discovery Matters
Imagine a lab network containing:
192.168.1.10 → Linux Server 192.168.1.11 → Windows VM 192.168.1.12 → Web Server 192.168.1.13 → Database VM
A host-discovery scan can help you identify systems that respond to the discovery methods being used.
Remember that network controls can cause some hosts not to respond to particular discovery probes.
Service and Version Detection
Finding an open port is only the beginning.
Suppose Nmap reports:
80/tcp open http
You may want to know what web server is actually running.
Use:
nmap -sV 127.0.0.1
The -sV option enables service/version detection.
According to the official documentation, Nmap uses service probes to identify services and, where possible, application names and version information. (Official Service and Version Detection Guide)
Example output may look like:
PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 80/tcp open http Apache
The exact results depend on the target.
Why Version Detection Is Useful
Imagine finding:
80/tcp open http
That tells you a web service is available.
But:
80/tcp open http Apache
gives you additional information about the service.
Version information can help administrators identify outdated software and determine which systems require maintenance or security review.
Operating System Detection
Nmap can attempt operating-system detection with:
sudo nmap -O 127.0.0.1
The -O option enables OS detection.
Nmap attempts to infer characteristics of the target operating system from responses to its probes.
OS detection may not always identify the system perfectly. Network filtering, virtualization and other factors can affect the results.
Aggressive Detection
Nmap also provides the -A option.
nmap -A 127.0.0.1
According to Nmap's documentation, -A enables several advanced detection features, including OS detection, version detection, script scanning and traceroute-related functionality. (Nmap Reference Guide)
Because this performs more checks, it is best used in your own lab or an explicitly authorized environment.
Nmap Default Scripts
Nmap includes the Nmap Scripting Engine (NSE).
NSE allows scripts to extend Nmap's capabilities for tasks such as service discovery, security checks and information gathering.
A common command is:
nmap -sC 127.0.0.1
The -sC option runs the default category of NSE scripts.
Use scripting only where you are authorized to perform the corresponding checks.
The official Nmap reference guide documents NSE as a major part of the tool's capabilities. (Nmap Reference Guide)
TCP SYN Scan
One of Nmap's well-known scanning methods is the TCP SYN scan:
sudo nmap -sS 127.0.0.1
The -sS option performs a TCP SYN scan.
At a conceptual level, Nmap uses TCP behavior to infer whether ports are open, closed or filtered.
You do not need to understand the packet-level details immediately. First learn how to interpret the resulting port states.
TCP Connect Scan
Nmap can also perform a TCP connect scan:
nmap -sT 127.0.0.1
The -sT method uses the operating system's normal connection mechanism.
The actual scanning method available or selected can depend on privileges and operating-system behavior.
UDP Scanning
Nmap can also scan UDP ports.
sudo nmap -sU 127.0.0.1
UDP scanning can be slower and can produce states such as open|filtered because UDP does not use the same connection process as TCP.
Only perform UDP scans against systems that you are authorized to assess.
Scan a Specific UDP Port
sudo nmap -sU -p 53 127.0.0.1
This is useful when testing a service in your own lab.
Fast Scan
Nmap provides a fast-scan option:
nmap -F 127.0.0.1
The -F option reduces the set of ports scanned compared with broader scans.
This is useful when you want a quick initial check.
Increase Scan Speed
Nmap provides timing templates such as:
nmap -T4 127.0.0.1
The timing templates range from slower and more cautious behavior to faster scanning.
Faster does not always mean better.
Increasing scan speed can affect accuracy, network load and the way network defenses respond.
Use aggressive timing carefully and primarily in controlled environments.
Disable Host Discovery
Sometimes you already know a target is online and want Nmap to skip host discovery.
nmap -Pn 192.168.1.10
The -Pn option treats the host as online instead of relying on host-discovery checks to decide whether to scan it.
This can be useful when discovery traffic is filtered.
Scan Only Selected TCP Ports
You can specify a list:
nmap -p 22,80,443 127.0.0.1
Or a range:
nmap -p 1-1024 127.0.0.1
This is a good way to practice without immediately scanning every port.
Scan Top Ports
Nmap also supports selecting a number of commonly used ports:
nmap --top-ports 20 127.0.0.1
You can change the number according to the needs of your authorized lab test.
Verbose Mode
Verbose mode provides more information while the scan is running.
nmap -v 127.0.0.1
For even more output, Nmap supports higher verbosity levels:
nmap -vv 127.0.0.1
This can help beginners understand what the tool is doing.
Save Nmap Results to a File
Saving scan results is important for documentation and comparison.
Normal Output
nmap -oN scan.txt 127.0.0.1
XML Output
nmap -oX scan.xml 127.0.0.1
Grepable Output
nmap -oG scan.gnmap 127.0.0.1
All Major Output Formats
nmap -oA myscan 127.0.0.1
The -oA option saves output in multiple formats using the specified base filename.
Why Save Scan Results?
Imagine you scan your own lab today:
22/tcp open ssh 80/tcp open http
After you change the server configuration, you scan again:
80/tcp open http
You can compare the two reports and confirm that SSH is no longer exposed.
This makes Nmap useful for network inventory and security validation, not just one-time experiments.
Scanning Multiple Hosts
You can specify multiple IP addresses:
nmap 192.168.1.10 192.168.1.11 192.168.1.12
You can also use a host range in an authorized environment:
nmap 192.168.1.10-20
Always verify that the targets are part of your authorized scope.
Scan a Domain You Are Authorized to Test
Nmap can accept hostnames:
nmap example.com
However, the fact that a website is publicly accessible does not mean that you have permission to scan it.
For learning, your safest options are:
- Your own computer
- Your own server
- Your own home lab
- Virtual machines
- Dedicated security-training targets
- Targets explicitly authorized for scanning
The Official scanme.nmap.org Practice Target
The Nmap Project provides scanme.nmap.org as a special target for practicing Nmap.
The official legal guide says this authorization is for Nmap scanning and does not extend to exploit testing or denial-of-service attacks. It also asks users not to initiate more than a dozen scans against the host per day to conserve bandwidth. (Nmap Legal Issues)
A basic authorized example is:
nmap scanme.nmap.org
Keep your practice limited to the permission provided by the Nmap Project.
A Beginner Nmap Workflow
Instead of randomly trying commands, follow a logical process.
1. Identify authorized target
↓
2. Check host availability
↓
3. Perform basic port scan
↓
4. Identify open ports
↓
5. Detect services
↓
6. Investigate configuration
↓
7. Document findings
↓
8. Fix unnecessary exposure
↓
9. Scan again
This workflow is much closer to how network assessment becomes useful in practice.
Example: Building a Small Local Lab
Suppose you have one Linux machine running locally.
First find your local addresses:
ip addr
Then check listening services:
ss -tuln
Now compare the operating system's local information with Nmap:
nmap 127.0.0.1
Then try service detection:
nmap -sV 127.0.0.1
This gives you a simple exercise:
Nmap and ss: Why Use Both?
ss shows local socket information from the system.
Nmap approaches the target from the network perspective.
This distinction is valuable.
| Tool | Perspective |
|---|---|
| ss | Local system |
| Nmap | Network view of the target |
Comparing both can help you understand firewall behavior and network exposure.
Nmap vs Netstat
Older Linux tutorials often introduce netstat.
Modern Linux systems frequently use ss instead.
Nmap serves a different purpose because it is designed for network discovery and scanning rather than simply displaying local socket information.
Nmap vs Ping
These tools answer different questions.
Ping:
ping 192.168.1.10
Primarily tests basic IP-level reachability using ICMP echo behavior when permitted.
Nmap:
nmap 192.168.1.10
Can investigate ports, services and other network characteristics.
A host can be reachable while not responding to ping, because network controls may filter ICMP.
Common Nmap Options Cheat Sheet
| Option | Purpose |
|---|---|
| -sn | Host discovery without a port scan |
| -sS | TCP SYN scan |
| -sT | TCP connect scan |
| -sU | UDP scan |
| -sV | Service/version detection |
| -O | OS detection |
| -A | Several advanced detection features |
| -sC | Default NSE scripts |
| -p | Specify ports |
| -p- | Scan all TCP ports |
| -F | Fast scan |
| -Pn | Skip host discovery assumption |
| -v | Verbose output |
| -oN | Normal output file |
| -oX | XML output |
| -oG | Grepable output |
| -oA | Save multiple output formats |
| --top-ports | Scan selected common ports |
| -T4 | Use a faster timing template |
Useful Beginner Commands
Basic Scan
nmap 127.0.0.1
Specific Ports
nmap -p 22,80,443 127.0.0.1
Service Detection
nmap -sV 127.0.0.1
OS Detection
sudo nmap -O 127.0.0.1
Default Scripts
nmap -sC 127.0.0.1
All TCP Ports
nmap -p- 127.0.0.1
Save Results
nmap -oA lab-scan 127.0.0.1
How to Read an Nmap Scan Like a Beginner
Suppose you receive:
PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 443/tcp open https 8080/tcp open http-proxy
Do not immediately think:
"I found four vulnerabilities."
You have not.
You have found four network services that appear accessible.
The next questions should be:
- Are these services expected?
- Who needs them?
- Are they securely configured?
- Are the versions current?
- Should any service be restricted?
- Is the exposure intentional?
This is the difference between scanning and security analysis.
Nmap Does Not Automatically Mean Vulnerability
This is an important concept.
An open port is not automatically a vulnerability.
For example:
443/tcp open https
This may simply mean the server intentionally provides a secure web service.
The security question is whether the service is appropriately configured, maintained and exposed.
Common Beginner Mistakes With Nmap
1. Scanning Random Public IP Addresses
Do not assume that a publicly reachable system is available for testing.
2. Using Aggressive Options Immediately
Start with simple scans and learn how to interpret the results.
3. Treating Every Open Port as a Vulnerability
Open services can be completely legitimate.
4. Ignoring Scope
In professional security assessments, scan only the systems and address ranges included in the authorized scope.
5. Focusing on Commands Instead of Networking
Understanding TCP, UDP, IP addresses, ports, routing and firewalls makes Nmap much easier to understand.
6. Not Saving Results
Always document significant authorized assessments.
7. Ignoring False Positives and Limitations
Nmap makes inferences from network responses. Detection results are not perfect and should be interpreted carefully.
Nmap and Firewalls
Firewalls can affect scan results.
For example, a firewall may:
- Allow traffic
- Reject traffic
- Drop traffic silently
- Allow only certain source addresses
- Allow only particular ports
This can produce different Nmap states.
For example:
Port A → open Port B → closed Port C → filtered
Understanding why the results differ requires networking knowledge.
How Nmap Fits Into a Security Assessment
A simplified authorized security workflow may look like:
Scope ↓ Asset Discovery ↓ Port Scanning ↓ Service Identification ↓ Configuration Review ↓ Vulnerability Assessment ↓ Risk Analysis ↓ Remediation ↓ Verification ↓ Report
Nmap is mainly useful during discovery and service-identification stages, though its other capabilities can support additional assessment tasks.
Mini Nmap Lab for Beginners
Try this sequence on your own machine.
Step 1 — Check Local Services
ss -tuln
Step 2 — Perform Basic Nmap Scan
nmap 127.0.0.1
Step 3 — Scan Common Ports
nmap --top-ports 20 127.0.0.1
Step 4 — Detect Services
nmap -sV 127.0.0.1
Step 5 — Scan All TCP Ports
nmap -p- 127.0.0.1
Step 6 — Save Results
nmap -oA first-lab-scan 127.0.0.1
Step 7 — Document What You Learned
Write down:
- Which ports were open?
- Which services were identified?
- Which ports did you expect?
- Were any unexpected services visible?
- What configuration changes could reduce unnecessary exposure?
Beginner Nmap Learning Roadmap
Networking Fundamentals
↓
TCP / UDP
↓
Ports and Services
↓
Basic Nmap
↓
Host Discovery
↓
Port States
↓
Service Detection
↓
OS Detection
↓
NSE
↓
Output and Reporting
↓
Authorized Security Labs
What Should You Learn Before Nmap?
For better results, learn these concepts first:
- IP addresses
- TCP and UDP
- Ports
- DNS
- Routing
- Firewalls
- Network interfaces
- Basic Linux commands
Our earlier CodeWithAV articles on networking and Linux can help build this foundation.
What Should You Learn After Nmap?
Once you understand basic Nmap, continue with:
- Wireshark
- Web application security
- Burp Suite
- OWASP fundamentals
- Vulnerability management
- Security logging
- Network defense
- Penetration-testing methodology
The goal should be to understand why a result matters, not just how to produce it.
Frequently Asked Questions
1. Is Nmap a hacking tool?
Nmap is a network exploration and security-auditing tool. It is used by administrators and security professionals for legitimate network discovery, inventory and testing. Whether its use is appropriate depends on authorization and how it is used.
2. Is Nmap free?
Yes. Nmap is free and open-source software. The official Nmap site provides downloads and documentation. (Nmap Official Website)
3. Is Nmap legal?
The legality of scanning depends on the jurisdiction, circumstances and authorization involved. The Nmap Project recommends securing written authorization before scanning networks and explains that users should understand applicable rules and provider policies. (Nmap Legal Guidance)
4. Can I scan my own computer?
Yes. Scanning systems you own or are explicitly authorized to test is the appropriate way to practice.
5. What does an open port mean?
An open port indicates that Nmap has determined that an application is listening and accepting relevant network communication on that port.
6. Does an open port mean the system is vulnerable?
No. An open port simply indicates an accessible service. You need additional analysis to determine whether a service is unnecessarily exposed, outdated or insecurely configured.
7. What is the difference between -sS and -sT?
-sS performs a TCP SYN scan, while -sT performs a TCP connect scan. The exact behavior and privilege requirements depend on the operating system and environment.
8. What is -sV?
-sV enables service and version detection, allowing Nmap to probe discovered services and attempt to identify the application and version.
9. What is -O?
-O enables operating-system detection. Nmap attempts to infer the target's operating-system characteristics from network responses.
10. What is NSE?
NSE stands for Nmap Scripting Engine. It allows scripts to extend Nmap for additional discovery, information gathering and security-related checks.
11. What is the safest Nmap target for beginners?
Your own computer or a deliberately created virtual-machine lab is the safest starting point. The Nmap Project also provides scanme.nmap.org as an explicitly authorized Nmap practice target with usage restrictions. (Official Scanme Guidance)
12. Can Nmap crash a server?
Most ordinary scans are designed for network discovery and auditing, but unexpected behavior or fragile systems can create problems. The safest approach is to scan authorized systems and begin with conservative tests.
Final Thoughts
Nmap is one of the most useful tools for learning the relationship between networking and cybersecurity.
But learning Nmap is not about memorizing hundreds of commands.
Start with a few fundamental concepts:
Practice first on 127.0.0.1, your own virtual machines and authorized training environments.
Once you understand what Nmap is actually telling you, commands such as -sV, -O, -p, -sn and -oA become much easier to understand.
Most importantly, remember that network visibility is not the same thing as vulnerability.
A professional security mindset asks:
That is the mindset worth developing as you continue your cybersecurity journey.
Recommended Reading on CodeWithAV
- Cybersecurity Roadmap for Beginners
- 50 Linux Commands for Cybersecurity Beginners
- What Is Ethical Hacking?
- What Is Penetration Testing?
- What Is a Firewall?
Tip: Replace the homepage URLs above with the exact URLs of the corresponding CodeWithAV posts after publication.
Official Nmap Resources
- Nmap Official Introduction
- Nmap Reference Guide
- Service and Version Detection
- Nmap Legal Issues and Authorized Scanning
- Official Nmap Download Page
- Nmap Network Scanning — Official Guide
Disclosure: Some links on CodeWithAV may be affiliate links. If you purchase a product or service through an affiliate link, we may earn a commission at no additional cost to you. We aim to recommend products and services based on their relevance to our readers.