Active reconnaissance is the first phase of any security audit. Nmap (Network Mapper) is the industry-standard tool for discovering open ports and mapping host parameters.
1. Standard SYN Scan (-sS)
Often called a “stealth scan,” the TCP SYN scan sends a SYN packet to target ports. If it receives a SYN-ACK, it indicates the port is open. Nmap sends a RST (Reset) packet instead of completing the 3-way handshake, minimizing logs on target systems.
nmap -sS -pn 192.168.1.1
2. Service Version Detection (-sV)
Obtaining open port numbers is not enough; we must find the exact software and version version running on those ports to identify vulnerable setups.
nmap -sV 192.168.1.1
3. Nmap Scripting Engine (NSE)
NSE scripts automate vulnerability verification. The “vuln” script suite queries public CVE databases to verify if target services are exploitable.
nmap --script vuln 192.168.1.1