Skip to content

Nmap

Discover hosts and services on a network. Port scanning, OS detection, version detection, and scripting engine.

Self-hostedNot yet verified
Report issueDemo online
MIT★ 11500

Open the official app on nmap.org

This tool is hosted by its maintainers. Click below to open nmap.org in a new tab — it's their official demo.

Browse security tools →

What's next with Nmap?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Nmap?

Nmap (Network Mapper) is a free and open-source security scanner designed for network discovery, host identification, and vulnerability assessment. Developed by Gordon Lyon (Fyodor), it enables users to analyze network infrastructure by probing hosts and services, making it an essential tool for cybersecurity professionals, network administrators, and penetration testers. Its primary purpose is to map network topology, detect active devices, and identify potential security weaknesses. Nmap addresses the challenge of understanding complex network environments by automating tasks like port scanning, OS detection, and service versioning. It is widely used in ethical hacking, system administration, and security audits to ensure network resilience against threats.

How it works

Nmap is a command-line tool that sends packets to network devices to determine which hosts are active, what services they offer, and their operating system configurations. It operates by leveraging TCP/IP protocols to interact with networked systems, providing detailed insights into network architecture. The tool is primarily used for network inventory, security auditing, and vulnerability scanning. Its ability to quickly assess large networks makes it indispensable for identifying misconfigurations, outdated software, and potential attack vectors. Nmap supports port scanning (e.g., TCP SYN, UDP, and ICMP scans), OS detection, version detection, and scripting for advanced tasks. For example, it can identify open ports (e.g., port 80 for HTTP) and determine if a host runs Windows or Linux. The NSE (Nmap Scripting Engine) allows users to run scripts for tasks like checking for vulnerabilities or exploiting known weaknesses.

How to use it

  1. 1Download Nmap from the official website (supporting Linux/macOS/Windows) or use a package manager. 2. Install the tool following platform-specific instructions, ensuring dependencies like Npcap are installed. 3. Run basic scans using commands like `nmap -sP 192.168.1.0/24` to discover active hosts. 4. Analyze results to identify open ports, services, and potential vulnerabilities. Practical tips: Use the GUI tool Zenmap for visual scanning, consult the Nmap documentation for advanced options, and verify results with GPG-signed releases to ensure authenticity.

What it can do

  • network port scanner

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/nmap/nmap
  • license: NPSL — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • For authorized use only — use on systems you own or have explicit permission to test.
  • Does not automatically patch vulnerabilities, requiring manual intervention
  • Requires direct network access to target systems, limiting use in segmented environments
  • May trigger firewall alerts due to high traffic volume during scans
  • Limited to TCP/UDP protocols without specialized hardware support

Understanding the result

Discover hosts and services on a network. Port scanning, OS detection, version detection, and scripting engine.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(nmap/nmap)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with nmap/nmap. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is Nmap and what does it do?

Nmap is a free, open-source network discovery and security auditing tool. It scans networks to identify active hosts, open ports, running services, and operating system details. It helps users map network infrastructure and assess security risks by detecting vulnerabilities and misconfigurations.

How does Nmap work technically?

Nmap sends crafted packets to target hosts and analyzes responses to infer network details. It uses TCP/IP protocols to probe ports (e.g., SYN packets for TCP scans) and leverages OS fingerprinting techniques to detect operating systems. The NSE scripting engine extends its capabilities by allowing custom scripts to interact with services and perform advanced tasks.

How do I scan a host for open ports?

Run the command `nmap -sV [IP_ADDRESS]` to scan a host. The `-sV` option enables version detection, revealing services like Apache HTTP Server 2.4.10. For example, `nmap -sV 192.168.1.5` will check open ports and display service versions, helping identify potential exploits.

How does Nmap compare to alternatives like Nessus or OpenVAS?

Nmap focuses on network discovery and basic vulnerability detection through scripting, while Nessus and OpenVAS are dedicated vulnerability scanners with deeper threat intelligence databases. Nmap is faster for large-scale network mapping, but tools like OpenVAS offer continuous monitoring and compliance checks that Nmap lacks.

How do I troubleshoot permission errors when running Nmap?

Permission errors often occur when running scans without elevated privileges. Use `sudo` on Linux/macOS (e.g., `sudo nmap -sP 192.168.1.0/24`) or run Nmap as an administrator on Windows. If issues persist, check firewall settings or use the `-v` flag for verbose output to identify blocked packets.

Spotted something wrong with Nmap, or want to maintain it? See how to help.