MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Nmap for beginners: your first controlled scan

Use a narrow TCP scan in your own lab and distinguish open, closed and filtered ports.

Before you start

Free Nmap and an explicitly authorised lab host; no production-wide scan required.

Define scope before the command

Nmap discovers hosts and inspects network services. Install it from the official project or your distribution's trusted repository. Scanning your own lab is a useful way to learn; permission to visit a website is not permission to scan all of its infrastructure.

Record the target, allowed ports and time window. Use one lab computer rather than a wide network range for the first exercise. Do not include printers, medical devices or other fragile equipment in an exploratory scan.

Check installation

bash
nmap --version

Scan a small port set

Replace the example with the real IP of your authorised lab host:

bash
nmap -sT -n -p 22,80,443 192.168.50.10

The TCP connect scan can run without raw-packet privileges on common systems. The numeric option avoids reverse-DNS lookups. This checks a specific set of TCP ports; it does not test every protocol or prove the host has no vulnerabilities.

Read the state, not just the service label

Open means a service accepted the relevant connection/probe. Closed indicates the target responded but no service was available on that port. Filtered means Nmap could not establish the state because probes or responses were blocked or otherwise inconclusive.

The service column can come from a port-number database. Seeing http beside port 80 does not prove a particular web server or version is installed. Use application checks and an appropriately scoped version query when needed.

Verify in the lab

On a Linux target, compare with sudo ss -lntp. On Windows, use Get-NetTCPConnection -State Listen. Explain why a local listener might still be filtered or unreachable from the scan computer: bind address, host firewall and routing all matter.

If the host is reported down, confirm its address and connectivity before changing scan options. The separate port-check tutorial explains when a single-host -Pn test is appropriate.

Common mistakes

Using aggressive all-feature options at the start increases activity and complexity without answering the basic question. An open port is not automatically a vulnerability. A filtered result is not proof of a secure service. Record the vantage point and time so later comparisons are meaningful.

Keep useful notes

Write down the command, target, expected services and observed states. Remove temporary lab listeners after practice. The goal is an explainable network observation, not the largest possible scan output.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.