If you specifie the class, it’ll search all ip in that class range:


Input from list of hosts/networks:

-iL filename

Output in (fname.nmap fname.xml fname.gnmap):

-oA fname

Increase verbosity level (use -vv or more for greater effect):


Reverse DNS.


Force send TCP SYN packet (use raw socket, need root):


Use ACK scan (use on open and filtered ports):


if (unfiltered) ‘stateless firewall’ else if (all result filtered) ‘stateful firewall’

UDP scan:


Probe open ports to determine service/version info:


Enable OS detection:


Enable OS detection, version detection, script scanning, and traceroute:


Treat all hosts as online (skip ACK on 80,443 and ICMP PING,TIMESTAMP):


Scan all possible ports:


Scan <number> most common ports (http://nmap.org/presentations/BHDC08/):

--top-ports <number>

