Mastering Nmap for Network Enumeration
8/17/20268 min read
Learning Nmap Through Hack The Box: Network Enumeration Notes
This week, I continued my journey through Hack The Box and spent more time exploring the network-enumeration toolkit, particularly Nmap.
Nmap, short for Network Mapper, is one of those tools that can look simple at first but gets significantly more powerful the deeper you go. At its most basic level, it can answer questions like:
Is this host online?
What ports are open?
What services are listening?
What versions of those services are running?
What operating system might the host be using?
Are firewalls or filtering devices changing what I can see?
What path is my traffic taking to reach the target?
That makes Nmap useful in a lot of different roles. A network engineer can use it to validate services and troubleshoot connectivity, while cybersecurity professionals can use it for asset discovery, enumeration, and authorized security testing. It also happens to be one of the most useful tools you can have while working through CTFs.
I completed two CTFs on Hack The Box this week and also signed up to join a team, so apparently I am trying to improve my networking skills in both the TCP/IP domain and the human domain.
One thing Hack The Box has reinforced for me is that enumeration is not just about running one giant scan and waiting for Nmap to tell you what to do next. It is more about forming a hypothesis, running a scan, looking at the response, adjusting your approach, and then digging deeper.
We even ran into an interesting situation recently where our commands and methodology appeared correct, but the target was not behaving the way it should. After resetting both the HTB target and the VM I was using, things suddenly started working.
So there was another important CTF lesson:
Sometimes the problem is your enumeration technique. Sometimes the lab is just being weird. Validate both before completely changing your methodology.
Disclaimer: Everything discussed here should only be performed against systems and networks you own or have explicit permission to test. I personally use Hack The Box and my own Proxmox homelab containing intentionally vulnerable systems such as Metasploitable and various operating-system VMs for testing.
Nmap Notes From the Lab
Host Discovery
Before scanning ports, Nmap normally performs host discovery to determine whether a target appears to be online.
One useful option in CTF environments is:
-Pn
This tells Nmap to skip host discovery and assume the target is online.
That can be useful when a firewall blocks the probes Nmap normally uses for host discovery. A system may be completely operational even though it does not respond to a traditional ping.
Example:
nmap -Pn 10.10.10.10
Another option is:
-sn
This performs host discovery without conducting a port scan.
Example:
nmap -sn 192.168.1.0/24
This can be useful when trying to identify active systems on a network before performing deeper enumeration.
TCP ACK Discovery — -PA
-PA sends TCP ACK probes during host discovery.
Example:
nmap -sn -PA80 10.10.10.10
An ACK probe can sometimes help identify hosts when other discovery methods are being filtered. However, I would not describe it as a universal "firewall bypass."
The important lesson is that different firewall configurations respond differently to different packet types.
If one discovery technique fails, another may still provide information.
ARP Discovery — -PR
-PR tells Nmap to use ARP requests for host discovery.
Example:
nmap -PR 192.168.1.0/24
ARP is especially useful when scanning systems on the same local Ethernet network.
Because ARP operates below the IP layer, normal IP firewall rules do not necessarily affect ARP discovery in the same way they affect TCP, UDP, or ICMP traffic.
However, saying that ARP "cannot be detected by firewalls" would be too broad. Network-monitoring and security systems can absolutely observe ARP traffic.
A better way to think about it is:
ARP discovery can be extremely reliable on the local LAN because the target needs ARP to communicate at Layer 2.
Timing Templates — -T
Nmap includes timing templates ranging from:
-T0 through -T5
These control how aggressively Nmap performs its scanning.
-T0 — Paranoid
Extremely slow.
Useful in very specialized situations where avoiding detection is more important than speed.
-T1 — Sneaky
Still extremely slow, but slightly faster than T0.
-T2 — Polite
Slows the scan down to reduce network utilization.
-T3 — Normal
Nmap's default timing behavior.
-T4 — Aggressive
This is probably the timing option I use the most in a controlled lab or CTF environment.
Example:
nmap -T4 10.10.10.10
T4 speeds up scanning considerably when working on a reasonably fast and reliable network.
One correction from my original notes: T4 is not the fastest setting.
-T5 — Insane
This is the fastest and most aggressive timing template.
It can sacrifice accuracy when network conditions are poor and generates traffic very quickly, making it much more obvious to monitoring systems.
For CTFs, T4 is usually a good balance between speed and reliability.
TCP Connect Scan — -sT
-sT performs a TCP Connect scan.
Example:
nmap -sT 10.10.10.10
This completes the normal TCP connection process using the operating system's networking functions.
The basic handshake looks like:
SYN → SYN/ACK → ACK
Because the connection is fully established, this technique is generally easier for systems to log and detect.
It is often described as being noisier than a SYN scan.
TCP SYN Scan — -sS
Another common option is:
-sS
This performs a TCP SYN scan, sometimes called a half-open scan.
Instead of completing the entire TCP handshake, Nmap observes the target's response to the SYN packet to determine the state of the port.
In Linux environments this normally requires elevated privileges.
Example:
sudo nmap -sS 10.10.10.10
SYN scanning is one of the most common techniques I have encountered while working through HTB.
OS Detection — -O
Nmap can attempt to identify the target operating system using:
-O
Example:
sudo nmap -O 10.10.10.10
Nmap analyzes characteristics of the target's network responses and compares them against its OS fingerprint database.
It is important to remember that this is fingerprinting, not magic.
Results may be exact, approximate, or completely inconclusive depending on the target and network conditions.
Service and Version Detection — -sV
-sV performs service and version detection.
Example:
nmap -sV 10.10.10.10
This is extremely useful during enumeration.
Instead of simply telling me:
80/tcp open http
Nmap might identify something more specific, such as the web server software and its version.
That information can then guide the next stage of enumeration.
One correction from my earlier notes:
-sV is not itself a vulnerability scan.
It identifies services and versions. I can then research those versions or use other tools and NSE scripts to investigate possible vulnerabilities.
This is also closely related to banner grabbing, although Nmap uses multiple service-detection techniques rather than relying exclusively on banners.
Aggressive Detection — -A
The -A option enables several advanced detection features at once.
Example:
nmap -A 10.10.10.10
It enables features including:
OS detection
Version detection
Default NSE script scanning
Traceroute
It is convenient, but it can also create substantially more traffic.
During CTFs, I generally prefer understanding and selecting the individual options I need rather than immediately throwing -A at everything.
Traceroute — --traceroute
Nmap can also attempt to determine the network path to the target:
nmap --traceroute 10.10.10.10
Traceroute can help show the intermediate network hops, usually routers or Layer 3 devices, between the scanner and the destination.
That can provide useful context about the network topology.
Reverse DNS — -R
-R tells Nmap to perform reverse DNS resolution for targets.
Example:
nmap -R 10.10.10.10
Instead of seeing only an IP address, reverse DNS may provide a hostname associated with that address.
Hostnames can sometimes reveal useful information about a network's structure, device purpose, environment, or naming conventions.
Packet Fragmentation — -f
Nmap can fragment IP packets using:
-f
Fragmentation breaks portions of the scan traffic into smaller IP fragments.
Historically, this could sometimes cause problems for firewalls or intrusion-detection systems that did not properly reconstruct fragmented traffic.
The default fragmentation behavior uses very small fragments, while specifying -f multiple times increases the fragment size.
Modern security devices are generally much better at reassembling and analyzing fragmented packets, so this is not some magical IDS bypass.
Still, it is useful for understanding how network-security devices inspect traffic.
Custom Fragment Size — --mtu
Nmap also allows a custom Maximum Transmission Unit value to be specified:
--mtu
For example:
nmap --mtu 16 10.10.10.10
The value needs to be a multiple of 8.
Common lab examples include:
8
16
24
32
This provides more control over how the packet fragmentation occurs.
Decoy Scanning — -D
Nmap's -D option allows the use of decoy addresses.
Conceptually, Nmap makes scan traffic appear alongside traffic associated with other IP addresses, making it more difficult to immediately determine which system initiated the scan.
Example syntax:
nmap -D RND:5 10.10.10.10
This should definitely stay inside an authorized lab environment.
It is also important to understand that decoys do not magically provide anonymity. Network infrastructure, routing information, logs, packet timing, and other telemetry can still expose the real scanning host.
Host Timeout — --host-timeout
If a system takes too long to scan, Nmap can stop scanning that host after a specified period.
Example:
nmap --host-timeout 30s 10.10.10.10
This can become useful when scanning multiple hosts and one system is significantly slowing down the overall process.
Nmap Scripting Engine
One of the most powerful components of Nmap is the Nmap Scripting Engine, or NSE.
NSE allows Nmap to run Lua-based scripts for tasks such as:
Service enumeration
Authentication checks
Banner gathering
Protocol enumeration
Web-server enumeration
Vulnerability checking
Network discovery
On many Linux installations, including Kali, the scripts can be found under:
/usr/share/nmap/scripts/
Scripts are executed using:
--script
For example:
nmap --script http-title -p80 10.10.10.10
Nmap also organizes scripts into categories.
One example is:
nmap --script vuln 10.10.10.10
The vuln category runs NSE scripts designed to check for known vulnerabilities.
Another tool I have encountered is Vulners, which can correlate discovered software versions with known vulnerabilities. Depending on the installation, the vulners NSE script may need to be installed separately rather than being available as part of a default Nmap installation.
Detecting Web Application Firewalls
A Web Application Firewall, or WAF, sits in front of a web application and attempts to identify and block malicious HTTP traffic.
Nmap includes NSE scripts that can help investigate whether a WAF may be present.
Examples include:
http-waf-detect
http-waf-fingerprint
For example:
nmap -p80,443 --script http-waf-detect 10.10.10.10
Detection does not necessarily mean the WAF can be bypassed. It simply gives me another piece of information about the environment I am investigating.
A CTF Enumeration Workflow
One habit I am starting to develop through Hack The Box is separating discovery from deeper enumeration.
Instead of immediately launching every Nmap feature possible, I might first determine what ports are available.
For example, in an authorized CTF environment:
nmap -Pn -p- -T4 <target>
Here:
-Pn assumes the target is online.
-p- scans all 65,535 TCP ports.
-T4 uses aggressive timing.
Once I identify the interesting ports, I can conduct a more focused scan against them.
For example:
nmap -sC -sV -p22,80,443 <target>
Here:
-sC runs Nmap's default NSE scripts.
-sV performs service/version detection.
-p22,80,443 limits the deeper enumeration to ports I already discovered.
I like this approach because it turns Nmap into an iterative investigation instead of a single command.
Find the ports.
Identify the services.
Understand the protocols.
Enumerate the applications.
Then decide what deserves further investigation.
That mindset has probably been one of the biggest lessons I have taken away from the CTFs so far.
Final Thoughts
The more I use Nmap, the more I realize that learning the switches is only part of learning the tool.
The more important skill is understanding why I am sending a particular probe and what the response tells me about the target.
What happens when ICMP is blocked?
What happens when I send a SYN versus completing the TCP handshake?
Why does ARP discovery work differently on the local network?
What information can a service banner reveal?
How does a firewall change what Nmap reports?
Those questions turn Nmap from a port scanner into a tool for actually understanding how a network behaves.
Hack The Box has been a great environment for practicing that process because CTFs force me to troubleshoot when my first idea does not work, challenge my assumptions, and occasionally spend an unreasonable amount of time debugging something only to discover that the target needed to be reset.
I suppose that is part of the learning experience too. Either way, the network-enumeration rabbit hole continues.
Links and Resources:
nmap.org | hackthebox.com |
