Network Enumeration & Discovery
Find hosts, open ports, and running services on your network.
Quick Reference
# Find all live hosts on subnet
nmap -sn 192.168.1.0/24
# Check ARP cache (recently seen hosts)
ip neigh | grep -E "192.168|10.50"
# Find hosts with specific port open
nmap -p 9090 --open 192.168.1.0/24
# Quick service scan on host
nmap -sV 192.168.1.201
# Full port scan
nmap -p- 192.168.1.201
Host Discovery
Ping Sweep (ARP on Local Network)
# Discover live hosts - no port scan
nmap -sn 192.168.1.0/24
Output
Nmap scan report for router.local (192.168.1.1)
Host is up (0.0023s latency).
Nmap scan report for 192.168.1.201
Host is up (0.012s latency).
Nmap done: 256 IP addresses (4 hosts up) scanned in 2.45 seconds
Port Scanning
Find Hosts with Specific Port Open
# Find all hosts with port 9090 open (Cockpit, Prometheus, etc.)
nmap -p 9090 --open 192.168.1.0/24
Output
Nmap scan report for 192.168.1.201
Host is up (0.012s latency).
PORT STATE SERVICE
9090/tcp open zeus-admin
Nmap done: 256 IP addresses (4 hosts up) scanned in 28.96 seconds
|
|
Common Service Port Scans
# SSH servers
nmap -p 22 --open 192.168.1.0/24
# Web servers (HTTP/HTTPS)
nmap -p 80,443 --open 192.168.1.0/24
# Cockpit / KVM management
nmap -p 9090 --open 192.168.1.0/24
# VNC servers
nmap -p 5900-5910 --open 192.168.1.0/24
# RDP servers
nmap -p 3389 --open 192.168.1.0/24
# Database servers
nmap -p 3306,5432,1521,27017 --open 192.168.1.0/24
Service Detection
Output Formats
Common Errors
See Also
-
Netcat Operations - Manual port probing and banner grabbing
-
tcpdump - Packet capture and analysis
-
Connectivity - Basic network troubleshooting