2.2 Network Mapping & Port Scanning with Nmap

Key Takeaways

  • Network host discovery leverages ARP requests on local subnets (arp-scan -l, nmap -PR) and ICMP/TCP ping sweeps across routed networks (nmap -sn).

  • The TCP SYN scan (-sS) maintains a half-open state by sending an immediate RST upon receiving SYN/ACK, offering high performance and stealth while requiring raw socket root privileges.

  • The TCP Connect scan (-sT) completes the three-way handshake using the standard OS socket API without requiring administrative privileges, but generates application-level connection logs.

  • UDP port scanning (-sU) is connectionless and slow due to OS-level ICMP rate limiting; absence of response indicates open|filtered, while ICMP port unreachable signifies closed.

  • Timing template -T4 optimizes probe intervals and timeouts for reliable lab networks, while flags like -Pn bypass ICMP blocking firewalls by forcing immediate port scanning.

Last updated: October 2026

Active Network Mapping & Host Discovery

Once passive intelligence gathering defines the target's external footprint, penetration testers transition to active reconnaissance. The foundational objective of active scanning is network mapping: identifying which target IP addresses are actively responsive (alive) and determining which transport layer ports are open to accept network connections. Nmap (Network Mapper) is the industry-standard security utility used to discover hosts, scan ports, and assess attack surfaces.

Layer 2 vs. Layer 3 Host Discovery

Host discovery operates fundamentally differently depending on whether the penetration tester resides on the same local Ethernet segment (Layer 2) or traverses an intermediate router to reach the target network (Layer 3).

Local Subnet Discovery (Layer 2 - ARP)

When scanning hosts on the same local Ethernet broadcast domain (such as a local subnet or a shared virtual laboratory switch), standard Layer 3 IP and ICMP packets cannot bypass the requirement for Layer 2 MAC address resolution. To deliver a packet to a local host, the scanner must resolve the target's IP address to a hardware MAC address via the Address Resolution Protocol (ARP).

Nmap automatically recognizes local subnets and employs ARP discovery (-PR):

# Perform a ping sweep on a local subnet using ARP
nmap -sn 192.168.1.0/24

# Utilize standalone arp-scan for rapid local subnet enumeration
arp-scan -l
arp-scan --interface=eth0 192.168.1.0/24

Note

ARP requests cannot be blocked by standard host-based software firewalls (such as Windows Defender Firewall or Linux iptables) because the host operating system's networking stack must answer ARP requests to maintain network connectivity on the local segment. Consequently, Layer 2 ARP discovery is virtually 100% reliable.

Routed Remote Discovery (Layer 3 - ICMP & TCP/UDP Probes)

When scanning targets across routers or across the Internet, ARP packets cannot cross routing boundaries. Nmap defaults to sending multiple probe packets to determine whether a remote host is active:

  1. ICMP Echo Request (Type 8)
  2. TCP SYN packet to port 443 (HTTPS)
  3. TCP ACK packet to port 80 (HTTP)
  4. ICMP Timestamp Request (Type 13)
# Ping sweep against a remote routed subnet without port scanning
nmap -sn 10.10.10.0/24

Handling Firewalls and Advanced Discovery Flags

Enterprise network firewalls and cloud security groups routinely drop inbound ICMP Echo requests (RFC 792) to hide perimeter assets. If Nmap sends discovery pings and receives no response, it marks the target as offline and skips port scanning entirely. Penetration testers utilize specialized discovery flags to circumvent this:

  • -Pn (Disable Host Discovery): Instructs Nmap to treat all target IP addresses as online, bypassing the ping phase entirely and initiating immediate port scans against every specified host. In penetration tests and lab examinations where targets are known to exist behind firewalls, -Pn is mandatory.
  • -PS<portlist> (TCP SYN Ping): Transmits empty TCP SYN packets to designated ports (e.g., -PS80,443,22,8080). If the target returns a SYN/ACK (open port) or RST (closed port), the target stack is responsive, confirming the host is alive.
  • -PA<portlist> (TCP ACK Ping): Transmits TCP ACK packets to specified ports (e.g., -PA80,3389). Because stateful firewalls track connections and expect a preceding SYN, an unsolicited ACK penetrates stateless packet filters and prompts RFC-compliant target stacks to return a RST, confirming the host is up.
  • -PU<portlist> (UDP Ping): Sends empty UDP datagrams to high or uncommon ports (e.g., -PU40125). If the host is active, it returns an ICMP Port Unreachable error.

Port Scanning Mechanics: TCP SYN vs. TCP Connect

Transport Control Protocol (TCP) communication relies on a deterministic three-way handshake: the client transmits a SYN, the server answers with SYN/ACK, and the client finalizes connection establishment with ACK.

TCP SYN Scan (-sS - "Half-Open" Scanning)

The TCP SYN scan (invoked with -sS) is Nmap's default and most popular scan type when executed with administrative privileges. It is termed a "half-open" scan because it intentionally prevents the TCP connection from fully establishing.

Detailed Packet Exchange:

  1. Attacker to Target: The scanner transmits a raw TCP packet with the SYN flag set to the target port.
  2. Target to Attacker:
    • Open Port: The target responds with a TCP packet containing the SYN/ACK flags.
    • Closed Port: The target responds with a TCP packet containing the RST/ACK flags.
    • Filtered Port: The target returns no response within the timeout threshold, or an intermediate firewall returns an ICMP unreachable error (Type 3 Code 1, 2, 3, 9, 10, or 13).
  3. Attacker to Target: Upon receiving the SYN/ACK indicating an open port, Nmap's raw socket engine immediately transmits a RST (Reset) packet rather than the final ACK. The connection is torn down instantly.

Key Characteristics:

  • Stealth Advantages: Because the TCP three-way handshake is never completed, the operating system kernel does not pass an established connection to the application layer. Many legacy application daemons (web servers, FTP services) log events only upon completed handshakes, allowing SYN scans to evade rudimentary application-level access logs.
  • High Performance: Eliminating the final ACK and subsequent graceful teardown packets (FIN/ACK) reduces bandwidth consumption and scan duration.
  • Privilege Requirement: Constructing custom, raw IP/TCP packets without operating system kernel intervention requires raw network socket privileges. On Linux, this requires root execution or running via sudo.

TCP Connect Scan (-sT)

The TCP Connect scan (invoked with -sT) is the default scanning technique used when the operator lacks administrative/root privileges.

Detailed Packet Exchange:

  1. Nmap invokes the high-level operating system network API using the Berkeley sockets connect() system call.
  2. The underlying host operating system kernel handles the entire three-way handshake: it sends a SYN, receives a SYN/ACK, and immediately replies with an ACK.
  3. Nmap records the port as open, and the socket is immediately closed by issuing a graceful close() or transmitting a RST.

Key Characteristics:

  • Unprivileged Execution: Does not require root privileges or raw socket manipulation; any standard, unprivileged user account can run a -sT scan.
  • Logging Footprint: Because the TCP connection fully establishes, the listening daemon accepts the socket, frequently generating entries in application connection logs (such as Apache access.log or Windows Event Logs).
  • Performance Overhead: Operating system socket abstraction introduces overhead, resulting in slightly slower scan speeds across large networks compared to SYN scans.

UDP Port Scanning Mechanics & Constraints

The User Datagram Protocol (UDP) is a connectionless, stateless protocol. Because UDP lacks handshakes, sequence numbers, and acknowledgments, scanning UDP ports (-sU) presents unique challenges.

Scanning Mechanics (-sU)

When Nmap executes a UDP scan, it constructs raw UDP datagrams. For common ports (such as port 53 for DNS, port 161 for SNMP, or port 67 for DHCP), Nmap sends service-specific application payloads; for unknown ports, it sends an empty packet:

  • Closed Port: If the UDP packet reaches an active host where no service listens on that port, RFC 792 mandates that the host operating system return an ICMP Type 3 Code 3 (Destination Unreachable: Port Unreachable) error packet. Nmap marks the port as closed.
  • Open Port: If the service receives the packet and transmits an application-layer UDP response (e.g., a DNS response or NTP time stamp), Nmap records the port as open.
  • Open|Filtered: If no packet is returned after multiple retransmissions, Nmap marks the port as open|filtered. In UDP, a listening service is not required to reply to an unrecognized datagram. Nmap cannot differentiate between a silent open service and a packet filter dropping the probe or the response.
  • Filtered: If the target returns ICMP Type 3 Unreachable errors with Codes 1, 2, 9, 10, or 13 (Communication Administratively Prohibited), Nmap marks the port as filtered.

The ICMP Rate Limiting Bottleneck

Under RFC 1812, operating systems restrict the frequency of outbound ICMP Destination Unreachable packets to protect network stability. The Linux kernel, for instance, limits ICMP error messages to one per second (icmp_ratelimit = 1000). Scanning all 65,535 UDP ports on a Linux host with default settings could take upwards of 18 hours.

To conduct effective UDP scanning during time-constrained penetration tests:

# Scan the top 100 most common UDP ports with -sU
nmap -sU --top-ports 100 -T4 target_ip

# Target specific high-value UDP services
nmap -sU -p 53,67,68,69,123,161,500 -T4 target_ip

Scan Optimization, Timing Templates, and Output Formats

Nmap Timing Templates (-T0 to -T5)

Nmap provides six predefined timing templates that regulate probe parallelism, packet timeouts, and delays between probe transmissions:

  • -T0 (Paranoid): Serial scanning (one port at a time), 5 minutes between probes. Used for extreme evasion of legacy IDS.
  • -T1 (Sneaky): 15 seconds between probes. Used for stealth.
  • -T2 (Polite): Slows the scan to consume minimal bandwidth and avoid crashing delicate target services.
  • -T3 (Normal): Default timing template. Dynamically adjusts timeouts based on network latency and packet loss.
  • -T4 (Aggressive): Recommended for penetration testing laboratories, CTFs, and reliable enterprise local networks. Caps maximum probe timeouts at 1.25 seconds and accelerates host discovery.
  • -T5 (Insane): Sacrifices accuracy for maximum velocity. Reduces probe timeouts to 5 milliseconds. Prone to false negatives due to packet loss.

Port Specification Syntax

By default, Nmap scans the top 1,000 most common ports identified in its nmap-services database. To modify port targets:

  • -p-: Scans all 65,535 TCP ports (1 through 65535). Essential in penetration tests to uncover services running on non-standard ports (such as HTTP on 8080, 8443, or 9001).
  • -p 1-1024: Scans well-known privileged system ports.
  • -p 22,80,443,445,3389: Scans an explicit comma-separated list of ports.
  • --top-ports <number>: Scans the top N ports (e.g., --top-ports 500).

Output Formats for Evidence and Pipeline Integration

Penetration testers document every scan for auditing, client reporting, and importing into post-exploitation frameworks:

  • -oN <file> (Normal): Human-readable standard Nmap console output saved to disk.
  • -oG <file> (Greppable): Formats results on a single line per host, facilitating command-line parsing with grep, awk, cut, and sed.
  • -oX <file> (XML): Structured XML output required for programmatic parsing and database importing into tools like Metasploit (db_import scan.xml), Faraday, or Dradis.
  • -oA <basename> (All Formats): Exports the scan results simultaneously into all three formats (basename.nmap, basename.gnmap, basename.xml). This represents standard industry best practice.
# Industry-standard baseline port scan across all ports
nmap -sS -p- -T4 -oA target_all_ports 10.10.10.15

Nmap Scan Types & Mechanics Comparison

Scan TypeNmap FlagTransport Protocol & Packet SequencePrivilege RequiredApplication Logging LikelihoodPrimary Penetration Testing Use Case
TCP SYN (Half-Open)-sSSYN -> SYN/ACK -> RSTRoot / Administrator (sudo)Low (bypasses application layer)Default primary scan; fast and accurate
TCP Connect-sTSYN -> SYN/ACK -> ACK -> RST/FINUnprivileged UserHigh (logged as completed connection)Executed when lacking root access
UDP Scan-sUUDP Datagram -> ICMP Port Unreach (closed)Root / Administrator (sudo)Low to ModerateIdentifies DNS, SNMP, DHCP, TFTP, IKE
TCP Null Scan-sNNo flags set (0) -> RST if closedRoot / Administrator (sudo)MinimalEvasion of non-stateful packet filters
TCP FIN Scan-sFFIN flag set -> RST if closedRoot / Administrator (sudo)MinimalBypasses simple stateless firewalls
TCP Xmas Scan-sXFIN, PSH, URG flags set -> RST if closedRoot / Administrator (sudo)MinimalRFC 793 compliance testing across Unix stacks
Test Your Knowledge

Why does an Nmap TCP SYN scan (-sS) require administrative (root or sudo) privileges to execute, whereas a TCP Connect scan (-sT) does not?

A

The TCP SYN scan encrypts outbound payloads using kernel cryptographic primitives

B

The TCP SYN scan crafts raw network packets to send a RST before completing the three-way handshake

C

The TCP Connect scan interacts directly with hardware network interface card firmware

D

The TCP SYN scan sends ICMP router advertisements that unprivileged sockets cannot generate

Test Your Knowledge

During a network assessment, an Nmap scan against a known live server returns 'Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn'. What does the -Pn option instruct Nmap to do?

A

Enable aggressive OS fingerprinting and bypass IP fragmentation filters

B

Perform an unprivileged UDP ping sweep across all ephemeral ports

C

Force the scanner to resolve hostnames via external authoritative DNS servers

D

Skip the preliminary host discovery phase and proceed directly to port scanning all specified targets

Test Your Knowledge

When executing a UDP port scan (nmap -sU), what does a port state of open|filtered signify?

A

The target host replied with an explicit TCP RST packet on the monitored port

B

The port responded with an ICMP Type 3 Code 3 (Port Unreachable) error message

C

The scanner received no response from the port, meaning it could either be open or filtered by a firewall

D

The service responded with an invalid cryptographic handshake rejecting the probe

Sections you finish are checked off in the contents.