2.2 Network Mapping & Port Scanning with Nmap
Key Takeaways
Network host discovery leverages ARP requests on local subnets (
arp-scan -l,nmap -PR) and ICMP/TCP ping sweeps across routed networks (nmap -sn).The TCP SYN scan (
-sS) maintains a half-open state by sending an immediate RST upon receiving SYN/ACK, offering high performance and stealth while requiring raw socket root privileges.The TCP Connect scan (
-sT) completes the three-way handshake using the standard OS socket API without requiring administrative privileges, but generates application-level connection logs.UDP port scanning (
-sU) is connectionless and slow due to OS-level ICMP rate limiting; absence of response indicatesopen|filtered, while ICMP port unreachable signifies closed.Timing template
-T4optimizes probe intervals and timeouts for reliable lab networks, while flags like-Pnbypass ICMP blocking firewalls by forcing immediate port scanning.
Active Network Mapping & Host Discovery
Once passive intelligence gathering defines the target's external footprint, penetration testers transition to active reconnaissance. The foundational objective of active scanning is network mapping: identifying which target IP addresses are actively responsive (alive) and determining which transport layer ports are open to accept network connections. Nmap (Network Mapper) is the industry-standard security utility used to discover hosts, scan ports, and assess attack surfaces.
Layer 2 vs. Layer 3 Host Discovery
Host discovery operates fundamentally differently depending on whether the penetration tester resides on the same local Ethernet segment (Layer 2) or traverses an intermediate router to reach the target network (Layer 3).
Local Subnet Discovery (Layer 2 - ARP)
When scanning hosts on the same local Ethernet broadcast domain (such as a local subnet or a shared virtual laboratory switch), standard Layer 3 IP and ICMP packets cannot bypass the requirement for Layer 2 MAC address resolution. To deliver a packet to a local host, the scanner must resolve the target's IP address to a hardware MAC address via the Address Resolution Protocol (ARP).
Nmap automatically recognizes local subnets and employs ARP discovery (-PR):
# Perform a ping sweep on a local subnet using ARP
nmap -sn 192.168.1.0/24
# Utilize standalone arp-scan for rapid local subnet enumeration
arp-scan -l
arp-scan --interface=eth0 192.168.1.0/24
Note
ARP requests cannot be blocked by standard host-based software firewalls (such as Windows Defender Firewall or Linux iptables) because the host operating system's networking stack must answer ARP requests to maintain network connectivity on the local segment. Consequently, Layer 2 ARP discovery is virtually 100% reliable.
Routed Remote Discovery (Layer 3 - ICMP & TCP/UDP Probes)
When scanning targets across routers or across the Internet, ARP packets cannot cross routing boundaries. Nmap defaults to sending multiple probe packets to determine whether a remote host is active:
- ICMP Echo Request (Type 8)
- TCP SYN packet to port 443 (HTTPS)
- TCP ACK packet to port 80 (HTTP)
- ICMP Timestamp Request (Type 13)
# Ping sweep against a remote routed subnet without port scanning
nmap -sn 10.10.10.0/24
Handling Firewalls and Advanced Discovery Flags
Enterprise network firewalls and cloud security groups routinely drop inbound ICMP Echo requests (RFC 792) to hide perimeter assets. If Nmap sends discovery pings and receives no response, it marks the target as offline and skips port scanning entirely. Penetration testers utilize specialized discovery flags to circumvent this:
-Pn(Disable Host Discovery): Instructs Nmap to treat all target IP addresses as online, bypassing the ping phase entirely and initiating immediate port scans against every specified host. In penetration tests and lab examinations where targets are known to exist behind firewalls,-Pnis mandatory.-PS<portlist>(TCP SYN Ping): Transmits empty TCP SYN packets to designated ports (e.g.,-PS80,443,22,8080). If the target returns aSYN/ACK(open port) orRST(closed port), the target stack is responsive, confirming the host is alive.-PA<portlist>(TCP ACK Ping): Transmits TCP ACK packets to specified ports (e.g.,-PA80,3389). Because stateful firewalls track connections and expect a preceding SYN, an unsolicited ACK penetrates stateless packet filters and prompts RFC-compliant target stacks to return aRST, confirming the host is up.-PU<portlist>(UDP Ping): Sends empty UDP datagrams to high or uncommon ports (e.g.,-PU40125). If the host is active, it returns an ICMP Port Unreachable error.
Port Scanning Mechanics: TCP SYN vs. TCP Connect
Transport Control Protocol (TCP) communication relies on a deterministic three-way handshake: the client transmits a SYN, the server answers with SYN/ACK, and the client finalizes connection establishment with ACK.
TCP SYN Scan (-sS - "Half-Open" Scanning)
The TCP SYN scan (invoked with -sS) is Nmap's default and most popular scan type when executed with administrative privileges. It is termed a "half-open" scan because it intentionally prevents the TCP connection from fully establishing.
Detailed Packet Exchange:
- Attacker to Target: The scanner transmits a raw TCP packet with the
SYNflag set to the target port. - Target to Attacker:
- Open Port: The target responds with a TCP packet containing the
SYN/ACKflags. - Closed Port: The target responds with a TCP packet containing the
RST/ACKflags. - Filtered Port: The target returns no response within the timeout threshold, or an intermediate firewall returns an ICMP unreachable error (Type 3 Code 1, 2, 3, 9, 10, or 13).
- Open Port: The target responds with a TCP packet containing the
- Attacker to Target: Upon receiving the
SYN/ACKindicating an open port, Nmap's raw socket engine immediately transmits aRST(Reset) packet rather than the finalACK. The connection is torn down instantly.
Key Characteristics:
- Stealth Advantages: Because the TCP three-way handshake is never completed, the operating system kernel does not pass an established connection to the application layer. Many legacy application daemons (web servers, FTP services) log events only upon completed handshakes, allowing SYN scans to evade rudimentary application-level access logs.
- High Performance: Eliminating the final
ACKand subsequent graceful teardown packets (FIN/ACK) reduces bandwidth consumption and scan duration. - Privilege Requirement: Constructing custom, raw IP/TCP packets without operating system kernel intervention requires raw network socket privileges. On Linux, this requires
rootexecution or running viasudo.
TCP Connect Scan (-sT)
The TCP Connect scan (invoked with -sT) is the default scanning technique used when the operator lacks administrative/root privileges.
Detailed Packet Exchange:
- Nmap invokes the high-level operating system network API using the Berkeley sockets
connect()system call. - The underlying host operating system kernel handles the entire three-way handshake: it sends a
SYN, receives aSYN/ACK, and immediately replies with anACK. - Nmap records the port as open, and the socket is immediately closed by issuing a graceful
close()or transmitting aRST.
Key Characteristics:
- Unprivileged Execution: Does not require root privileges or raw socket manipulation; any standard, unprivileged user account can run a
-sTscan. - Logging Footprint: Because the TCP connection fully establishes, the listening daemon accepts the socket, frequently generating entries in application connection logs (such as Apache
access.logor Windows Event Logs). - Performance Overhead: Operating system socket abstraction introduces overhead, resulting in slightly slower scan speeds across large networks compared to SYN scans.
UDP Port Scanning Mechanics & Constraints
The User Datagram Protocol (UDP) is a connectionless, stateless protocol. Because UDP lacks handshakes, sequence numbers, and acknowledgments, scanning UDP ports (-sU) presents unique challenges.
Scanning Mechanics (-sU)
When Nmap executes a UDP scan, it constructs raw UDP datagrams. For common ports (such as port 53 for DNS, port 161 for SNMP, or port 67 for DHCP), Nmap sends service-specific application payloads; for unknown ports, it sends an empty packet:
- Closed Port: If the UDP packet reaches an active host where no service listens on that port, RFC 792 mandates that the host operating system return an ICMP Type 3 Code 3 (Destination Unreachable: Port Unreachable) error packet. Nmap marks the port as
closed. - Open Port: If the service receives the packet and transmits an application-layer UDP response (e.g., a DNS response or NTP time stamp), Nmap records the port as
open. - Open|Filtered: If no packet is returned after multiple retransmissions, Nmap marks the port as
open|filtered. In UDP, a listening service is not required to reply to an unrecognized datagram. Nmap cannot differentiate between a silent open service and a packet filter dropping the probe or the response. - Filtered: If the target returns ICMP Type 3 Unreachable errors with Codes 1, 2, 9, 10, or 13 (Communication Administratively Prohibited), Nmap marks the port as
filtered.
The ICMP Rate Limiting Bottleneck
Under RFC 1812, operating systems restrict the frequency of outbound ICMP Destination Unreachable packets to protect network stability. The Linux kernel, for instance, limits ICMP error messages to one per second (icmp_ratelimit = 1000). Scanning all 65,535 UDP ports on a Linux host with default settings could take upwards of 18 hours.
To conduct effective UDP scanning during time-constrained penetration tests:
# Scan the top 100 most common UDP ports with -sU
nmap -sU --top-ports 100 -T4 target_ip
# Target specific high-value UDP services
nmap -sU -p 53,67,68,69,123,161,500 -T4 target_ip
Scan Optimization, Timing Templates, and Output Formats
Nmap Timing Templates (-T0 to -T5)
Nmap provides six predefined timing templates that regulate probe parallelism, packet timeouts, and delays between probe transmissions:
-T0(Paranoid): Serial scanning (one port at a time), 5 minutes between probes. Used for extreme evasion of legacy IDS.-T1(Sneaky): 15 seconds between probes. Used for stealth.-T2(Polite): Slows the scan to consume minimal bandwidth and avoid crashing delicate target services.-T3(Normal): Default timing template. Dynamically adjusts timeouts based on network latency and packet loss.-T4(Aggressive): Recommended for penetration testing laboratories, CTFs, and reliable enterprise local networks. Caps maximum probe timeouts at 1.25 seconds and accelerates host discovery.-T5(Insane): Sacrifices accuracy for maximum velocity. Reduces probe timeouts to 5 milliseconds. Prone to false negatives due to packet loss.
Port Specification Syntax
By default, Nmap scans the top 1,000 most common ports identified in its nmap-services database. To modify port targets:
-p-: Scans all 65,535 TCP ports (1through65535). Essential in penetration tests to uncover services running on non-standard ports (such as HTTP on 8080, 8443, or 9001).-p 1-1024: Scans well-known privileged system ports.-p 22,80,443,445,3389: Scans an explicit comma-separated list of ports.--top-ports <number>: Scans the top N ports (e.g.,--top-ports 500).
Output Formats for Evidence and Pipeline Integration
Penetration testers document every scan for auditing, client reporting, and importing into post-exploitation frameworks:
-oN <file>(Normal): Human-readable standard Nmap console output saved to disk.-oG <file>(Greppable): Formats results on a single line per host, facilitating command-line parsing withgrep,awk,cut, andsed.-oX <file>(XML): Structured XML output required for programmatic parsing and database importing into tools like Metasploit (db_import scan.xml), Faraday, or Dradis.-oA <basename>(All Formats): Exports the scan results simultaneously into all three formats (basename.nmap,basename.gnmap,basename.xml). This represents standard industry best practice.
# Industry-standard baseline port scan across all ports
nmap -sS -p- -T4 -oA target_all_ports 10.10.10.15
Nmap Scan Types & Mechanics Comparison
| Scan Type | Nmap Flag | Transport Protocol & Packet Sequence | Privilege Required | Application Logging Likelihood | Primary Penetration Testing Use Case |
|---|---|---|---|---|---|
| TCP SYN (Half-Open) | -sS | SYN -> SYN/ACK -> RST | Root / Administrator (sudo) | Low (bypasses application layer) | Default primary scan; fast and accurate |
| TCP Connect | -sT | SYN -> SYN/ACK -> ACK -> RST/FIN | Unprivileged User | High (logged as completed connection) | Executed when lacking root access |
| UDP Scan | -sU | UDP Datagram -> ICMP Port Unreach (closed) | Root / Administrator (sudo) | Low to Moderate | Identifies DNS, SNMP, DHCP, TFTP, IKE |
| TCP Null Scan | -sN | No flags set (0) -> RST if closed | Root / Administrator (sudo) | Minimal | Evasion of non-stateful packet filters |
| TCP FIN Scan | -sF | FIN flag set -> RST if closed | Root / Administrator (sudo) | Minimal | Bypasses simple stateless firewalls |
| TCP Xmas Scan | -sX | FIN, PSH, URG flags set -> RST if closed | Root / Administrator (sudo) | Minimal | RFC 793 compliance testing across Unix stacks |
Why does an Nmap TCP SYN scan (-sS) require administrative (root or sudo) privileges to execute, whereas a TCP Connect scan (-sT) does not?
The TCP SYN scan encrypts outbound payloads using kernel cryptographic primitives
The TCP SYN scan crafts raw network packets to send a RST before completing the three-way handshake
The TCP Connect scan interacts directly with hardware network interface card firmware
The TCP SYN scan sends ICMP router advertisements that unprivileged sockets cannot generate
During a network assessment, an Nmap scan against a known live server returns 'Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn'. What does the -Pn option instruct Nmap to do?
Enable aggressive OS fingerprinting and bypass IP fragmentation filters
Perform an unprivileged UDP ping sweep across all ephemeral ports
Force the scanner to resolve hostnames via external authoritative DNS servers
Skip the preliminary host discovery phase and proceed directly to port scanning all specified targets
When executing a UDP port scan (nmap -sU), what does a port state of open|filtered signify?
The target host replied with an explicit TCP RST packet on the monitored port
The port responded with an ICMP Type 3 Code 3 (Port Unreachable) error message
The scanner received no response from the port, meaning it could either be open or filtered by a firewall
The service responded with an invalid cryptographic handshake rejecting the probe
Sections you finish are checked off in the contents.