Nmap
A short wiki of Nmap scripts and tricks to use on different scenarios
Clickjacking Script
sudo nmap --script clickjacking-prevent-check -Pn -p 443 www.example.com -oN NmapClickJacking.txtDNS Cache Snooping
sudo nmap -sU -p 53 --script dns-cache-snoop.nse --script-args 'dns-cache-snoop.mode=timed,dns-cache-snoop.domains={www.google.com}' 192.168.1.253-Greppable Output
sudo nmap -PER -sn 192.168.1.0/24 -oG - | awk '/Up$/{print $2}nmap -n -sn 192.0.2.0/24 -oG - | awk '/Up$/{print $2}'Internal IP Leak
nmap --script http-internal-ip-disclosure -oN NmapIPLeak.txt www.example.comTerminal Services RDP
sudo nmap -p3389 --script rdp-enum-encryption 192.168.0.1Default Credential Scanning:
nmap -p80 --script http-default-accounts host/ipTelnet
Host Discovery
TCP Scan
All ports All Scripts (use sSV for version detection)
Top 1000 ports
UDP Scan Top 1000
UDP All ports
Find Hosts
Find Services
IP or File Exclusion
Scripts
NFS Share
LDAP Port 389
Nmap HTML Output Conversion
Nmap Timing Template
Maximum Retries (–max-retries)
Host-timeout
Hostgroup
Maximum rate (max-rate)
Minimum rate (min-rate)
Parallelism
Max-rtt-timeout
Output Live Machines on a network with Nmap
RAW Bash Script
Setting up Cron
Last updated