Skip to content

Naabu

Fast and reliable port scanner built for simplicity, with support for SYN, connect and UDP scans.

Self-hostedNot yet verified
Report issue
MIT★ 4500Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse network tools →

What's next with Naabu?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Naabu?

Naabu is a fast, reliable port scanning tool written in Go, designed for security professionals to identify open ports on target hosts during penetration testing and bug bounty assessments. It focuses on simplicity and efficiency, enabling users to quickly enumerate valid ports using SYN/CONNECT/UDP probes. The tool is particularly useful for security researchers and ethical hackers who need to map network attack surfaces without relying on resource-heavy alternatives. Naabu addresses the challenge of traditional port scanning by minimizing false positives and providing lightweight performance, making it ideal for environments where speed and accuracy are critical. Its integration with other tools like Nmap enhances its utility in comprehensive security workflows, allowing users to combine port discovery with service detection for deeper reconnaissance.

How it works

Naabu is a Go-based port scanner optimized for reliability and simplicity, prioritizing speed without sacrificing accuracy. It is designed to work alongside other security tools to streamline attack surface discovery in penetration testing and bug bounty programs. The primary purpose of Naabu is to rapidly identify open ports on target hosts by leveraging SYN/CONNECT/UDP scanning techniques. This allows security professionals to prioritize hosts and services for further analysis, reducing manual effort in reconnaissance phases. Naabu supports DNS port scanning, automatic IP deduplication for DNS targets, and IPv4/IPv6 scanning (with experimental support). It also integrates with Shodan for passive port enumeration, enabling users to gather data without active probing. The tool's NMAP integration allows for service detection post-port discovery, enhancing its versatility in security workflows.

How to use it

  1. 1Clone the repository: `git clone https://github.com/projectdiscovery/naabu.git`.
  2. 2Build the binary: `go build` or use Docker via `docker run`.
  3. 3Run a scan: `./naabu -u https://target.com` to scan a domain's IPs and ports.
  4. 4Analyze output: Naabu lists open ports and their responses, with options to filter results using flags like `-p` for specific ports. Practical tips include using the `-t` flag to adjust concurrency, `-s` for scan type (SYN/UDP), and `-o` to save results. Combining Naabu with Nmap via `--nmap` provides deeper service detection for identified open ports.

What it can do

  • port scanner

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/projectdiscovery/naabu
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • IPv6 scanning is experimental and may require additional configuration.
  • Relies on external services like Shodan for passive enumeration, which may have access restrictions.
  • UDP scanning can be unreliable due to protocol characteristics, leading to potential false negatives.
  • CDN/WAF exclusion requires manual tuning of filters, which may not cover all edge cases.
  • Lacks built-in support for advanced OS fingerprinting or version detection beyond port identification.

Understanding the result

Fast and reliable port scanner built for simplicity, with support for SYN, connect and UDP scans.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(projectdiscovery/naabu)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with projectdiscovery/naabu. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Naabu used for?

Naabu is used for rapid port scanning in security assessments, helping identify open ports on target hosts. It is commonly used in bug bounty programs and pentesting to map network attack surfaces efficiently. Its lightweight design and integration with tools like Nmap make it a valuable asset for security researchers needing quick reconnaissance.

How does Naabu perform port scanning?

Naabu uses SYN/CONNECT/UDP probes to scan ports, prioritizing speed and reliability. It sends probes to target ports and analyzes responses to determine if they are open. The tool minimizes false positives through features like automatic IP deduplication and DNS-specific scanning. UDP scans are particularly useful for identifying services that respond to UDP traffic, though they may have higher packet loss rates compared to TCP.

How do I scan a domain with Naabu?

To scan a domain, run `./naabu -u https://example.com` to automatically resolve the domain's IP addresses and scan their open ports. You can specify particular ports with `-p 80,443` or adjust concurrency with `-t 100` to control parallel scan requests. For advanced use, combine it with NMAP using `--nmap` to detect service versions on identified ports.

How does Naabu compare to Nmap?

Naabu is optimized for speed and simplicity, focusing on port discovery with minimal resource usage, while Nmap offers more advanced features like OS detection and vulnerability scanning. Naabu's integration with Nmap allows it to complement traditional scans, using Nmap for deeper service analysis after identifying open ports. Unlike Nmap, Naabu lacks built-in service detection but excels in rapid, lightweight reconnaissance.

What should I do if Naabu reports false positives?

False positives in Naabu can often be filtered using the CDN/WAF exclusion feature or by adjusting scan parameters like `-s` for scan type. If UDP ports appear closed, try increasing the scan timeout with `-w` or re-scanning with TCP. For persistent issues, validate results against passive data sources like Shodan or use NMAP for cross-checking.

Spotted something wrong with Naabu, or want to maintain it? See how to help.