Nmap Fundamentals: Complete Beginner’s Guide to Network Scanning
Nmap Fundamentals: Complete Beginner’s Guide to Network Scanning
Author
Abhishek Singh
Published
13 min read
Learn what Nmap is, how it works, what it can discover, how to understand its results, and how security professionals use it during authorized security assessments.
When a security professional begins assessing a network, one of the first questions is:
"What is actually exposed on this network?"
Before investigating vulnerabilities, applications, authentication mechanisms, or configuration weaknesses, an analyst needs to understand the environment.
Which systems are reachable?
Which ports are open?
Which services are running?
Which operating systems might be present?
Which systems should be investigated further?
This is where Nmap becomes extremely useful.
Nmap is one of the most widely used tools for network discovery and security auditing. It can help security professionals build an understanding of a network before moving into deeper assessment.
But Nmap is more than a command that prints a list of ports.
To use it effectively, you need to understand what it is doing and how to interpret what it tells you.
What Is Nmap?
Nmap, short for Network Mapper, is an open-source tool designed for network discovery and security auditing.
At a high level, Nmap sends specially constructed network probes to a target and analyzes the responses.
This allows it to gather information such as:
Whether a host is reachable
Which ports appear open
Which ports appear closed
Which ports may be filtered
Which services may be running
Which service versions may be present
Possible operating-system characteristics
Network configuration information
A simplified view looks like this:
TERMINAL OUTPUT
Nmap
|
v
+--------------+
| Target Host |
+--------------+
|
Network Responses
|
v
+--------------+
| Nmap Analysis|
+--------------+
|
v
Scan Results
The results then become information that a security analyst can investigate.
Imagine you are responsible for securing a company's server.
You know the server exists, but you don't know exactly what is exposed.
You might discover:
TERMINAL OUTPUT
22/tcp SSH
80/tcp HTTP
443/tcp HTTPS
3306/tcp MySQL
Now you have questions.
Why is SSH exposed?
Is the web application expected?
Does the database really need to be network-accessible?
Are these services patched?
Are firewall rules configured correctly?
Are there unnecessary services?
Nmap doesn't answer every security question.
Instead, it gives you visibility that allows you to ask better questions.
Nmap in a VAPT Methodology
Nmap is commonly useful during the early stages of an authorized security assessment.
A simplified VAPT workflow might look like:
TERMINAL OUTPUT
Scope
|
v
Reconnaissance
|
v
Host Discovery
|
v
Port Scanning
|
v
Service Enumeration
|
v
Application Analysis
|
v
Vulnerability Assessment
|
v
Validation
|
v
Reporting
Nmap is especially useful around:
Host discovery
Port scanning
Service enumeration
Initial network mapping
It can also provide information that supports later investigation.
Nmap Is Not a Magic Vulnerability Scanner
This is one of the most important concepts for beginners.
The result can provide more useful information than either action alone.
Saving Nmap Results
Security assessments need documentation.
You can save normal output with:
TERMINAL OUTPUT
nmap TARGET -oN scan.txt
The option:
TERMINAL OUTPUT
-oN
means normal output.
The results are written to:
TERMINAL OUTPUT
scan.txt
You can then view them with:
TERMINAL OUTPUT
cat scan.txt
This is useful for:
Evidence
Reports
Comparing scans
Lab documentation
Reviewing results later
Why Documentation Matters
Imagine your first scan shows:
TERMINAL OUTPUT
22
443
A later scan shows:
TERMINAL OUTPUT
22
443
8080
The new port could indicate a configuration change.
A security team can investigate:
TERMINAL OUTPUT
What changed?
Who changed it?
Why was the service added?
Is it authorized?
Should the firewall permit it?
This is one reason network scanning is useful for defensive security.
Nmap and Firewalls
Firewalls can affect Nmap results.
For example:
TERMINAL OUTPUT
Nmap
|
v
Firewall
|
v
Target
The firewall may:
Allow traffic
Reject traffic
Drop traffic
Filter specific ports
Apply network rules
This can cause ports to appear:
TERMINAL OUTPUT
open
closed
filtered
Therefore, scan results must always be interpreted in context.
Nmap and Operating-System Detection
Nmap can also attempt operating-system detection.
A commonly used option is:
TERMINAL OUTPUT
nmap -O TARGET
The -O option requests OS detection.
Nmap analyzes network behavior and compares it with known characteristics.
The result is an inference, not guaranteed truth.
Network devices, firewalls, virtualization, and unusual configurations can affect detection accuracy.
Nmap Scripting Engine
Nmap includes the Nmap Scripting Engine (NSE).
NSE allows scripts to extend Nmap's capabilities.
It can support activities such as:
Service enumeration
Network discovery
Configuration checks
Security auditing
Additional information gathering
For beginners, the important concept is:
TERMINAL OUTPUT
Nmap
+
NSE scripts
=
Extended functionality
NSE scripts should still be used only within an authorized scope.
Some scripts can generate significant traffic or perform intrusive checks, so understand what a script does before running it.
Nmap Output Is Evidence
A very important professional skill is learning to distinguish:
TERMINAL OUTPUT
Observation
from:
TERMINAL OUTPUT
Conclusion
For example:
Observation
TERMINAL OUTPUT
443/tcp is open.
Better investigation
TERMINAL OUTPUT
HTTPS appears to be exposed.
Security conclusion
TERMINAL OUTPUT
HTTPS exposure is unnecessary and represents a vulnerability.
The third statement requires additional evidence.
Don't jump from a scanner result directly to a security conclusion.
Nmap Limitations
Nmap is powerful, but it has limitations.
It may not accurately determine:
Every service
Every version
Every operating system
Every firewall rule
Every vulnerability
Results can be affected by:
Firewalls
IDS/IPS
Proxies
Network latency
Service configuration
Rate limiting
Virtualization
Network topology
Therefore:
Nmap results should be validated and interpreted by the analyst.
Nmap From an Attacker's Perspective
During an authorized penetration test, an assessor may use Nmap to understand the exposed attack surface.
For example:
TERMINAL OUTPUT
Target
|
+-- 22 SSH
|
+-- 80 HTTP
|
+-- 443 HTTPS
This information can help determine where deeper testing should occur.
Nmap From a Defender's Perspective
The same information is valuable to defenders.
A defender might ask:
TERMINAL OUTPUT
Why is SSH exposed?
Why is this database reachable?
Why is this development service running?
Which ports changed since last month?
This makes Nmap useful for:
Attack-surface management
Configuration validation
Security audits
Network inventory
Change monitoring
Common Beginner Mistakes
1. Thinking Every Open Port Is Vulnerable
Incorrect:
TERMINAL OUTPUT
Port 80 is open
↓
Vulnerability!
Correct:
TERMINAL OUTPUT
Port 80 is open
↓
Investigate the service
↓
Determine whether exposure is expected
↓
Assess security
2. Assuming Port Numbers Identify Services
Port 80 is commonly HTTP, but that doesn't guarantee HTTP is running there.
Always investigate.
3. Scanning Without Authorization
Never scan random systems.
Use Hackvora's provided sandbox targets.
4. Running Every Option at Once
More options do not automatically mean better results.
Start with the information you actually need.
5. Not Saving Results
Professional security work requires documentation.
Keep appropriate scan results for the assessment and reporting process.
Nmap Learning Path
A good progression is:
TERMINAL OUTPUT
Nmap Fundamentals
↓
Host Discovery
↓
Port Scanning
↓
Port States
↓
Service Detection
↓
Version Detection
↓
OS Detection
↓
NSE
↓
Enumeration
↓
VAPT Assessment
↓
Reporting
Don't try to memorize everything in one session.
Build the concepts progressively.
Hands-On Practice
Now move from theory to practice.
Hackvora provides a controlled environment where you can practice against an authorized target.
Exercise 1 — Basic Scan
Run:
TERMINAL OUTPUT
nmap TARGET
Record:
Open ports
Closed ports
Filtered ports
Services reported by Nmap
Exercise 2 — Service Detection
Run:
TERMINAL OUTPUT
nmap -sV TARGET
Compare the result with Exercise 1.
Ask:
What additional information did Nmap provide?
Exercise 3 — Selected Ports
Run:
TERMINAL OUTPUT
nmap -p 22,80,443 TARGET
Identify the state of each selected port.
Exercise 4 — Save Results
Run:
TERMINAL OUTPUT
nmap TARGET -oN scan.txt
Then:
TERMINAL OUTPUT
cat scan.txt
Confirm that the result was successfully saved.
Knowledge Check
You discover:
TERMINAL OUTPUT
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
443/tcp open https
3306/tcp open mysql
Which result deserves further investigation?
TERMINAL OUTPUT
A. SSH
B. HTTP
C. HTTPS
D. MySQL
Think Before Looking at the Answer
Don't simply choose based on the port number.
Ask:
What kind of service is this?
Should this service normally be exposed to this network?
What security controls should protect it?
Answer
D. MySQL
Port 3306 is commonly associated with MySQL.
However, the correct security conclusion is not:
"MySQL on 3306 is automatically a vulnerability."
Instead:
TERMINAL OUTPUT
3306 exposed
↓
Identify the service
↓
Determine why it is exposed
↓
Check network restrictions
↓
Review configuration
↓
Assess security impact
This is the mindset of a security analyst.
Nmap Cheat Sheet
Check Nmap version
TERMINAL OUTPUT
nmap --version
Basic scan
TERMINAL OUTPUT
nmap TARGET
Host discovery
TERMINAL OUTPUT
nmap -sn TARGET_RANGE
Selected ports
TERMINAL OUTPUT
nmap -p 22,80,443 TARGET
Port range
TERMINAL OUTPUT
nmap -p 1-1000 TARGET
All TCP ports
TERMINAL OUTPUT
nmap -p- TARGET
Service/version detection
TERMINAL OUTPUT
nmap -sV TARGET
OS detection
TERMINAL OUTPUT
nmap -O TARGET
Save normal output
TERMINAL OUTPUT
nmap TARGET -oN scan.txt
Read saved results
TERMINAL OUTPUT
cat scan.txt
Key Takeaways
You should now understand that Nmap is fundamentally about network visibility.
The core concepts are:
TERMINAL OUTPUT
Host
↓
Port
↓
Service
↓
Version
↓
Enumeration
↓
Analysis
Remember these principles:
Nmap is a network discovery and security-auditing tool.
An open port is not automatically a vulnerability.
Port numbers are conventions, not proof of a service.
Service detection can provide additional investigation context.
Firewalls and network conditions can affect scan results.
Scanner output should be treated as evidence and interpreted carefully.
Documentation is an important part of professional security work.
Always scan only systems you are authorized to assess.
Continue Learning
You have now learned the foundation of Nmap.
Continue with:
Next: Nmap Host Discovery
Learn how security professionals identify reachable systems within an authorized network.
Then continue to:
TERMINAL OUTPUT
Nmap Host Discovery
↓
Nmap Port Scanning
↓
Nmap Service Detection
↓
Nmap Enumeration
↓
VAPT Reconnaissance
The goal is not to memorize commands.
The goal is to understand what information you are trying to obtain, why you need it, and how to interpret it.