Executes systematic Nmap port scans and service detection while maintaining organized audit logs.

Install

mkdir -p .claude/skills/nmap && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/7880" && unzip -o skill.zip -d .claude/skills/nmap && rm skill.zip

Installs to .claude/skills/nmap

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Professional network reconnaissance and port scanning using nmap. Supports various scan types (quick, full, UDP, stealth), service detection, vulnerability scanning, and NSE scripts. Use when you need to enumerate network services, detect versions, or perform network reconnaissance.
283 chars✓ has a “when” triggerlonger than Claude Code's old 250-char listing cap (fine on current versions)
Intermediate

Key capabilities

  • Performs full-port TCP/SYN scanning
  • Executes host discovery bypass via -Pn
  • Automates service detection and NSE script execution
  • Generates structured XML and GNMAP output files

How it works

Executes a two-phase shell script routine that performs fast port discovery followed by targeted service enumeration based on identified open ports.

Inputs & outputs

You give it
Target IP or hostname
You get back
Organized directory containing port and service scan results

When to use nmap

  • Identify open ports on a target network
  • Detect service versions running on open ports
  • Perform reconnaissance for security audits

About this skill

Nmap Scan - Professional Network Reconnaissance

You are helping the user perform professional network reconnaissance and port scanning using nmap. This skill provides guidance for various scan types, output formats, and result analysis.

Output Directory

Directory Structure

nmap-output/
├── nmap-portscan.nmap      # Initial fast port discovery
├── nmap-portscan.xml
├── nmap-portscan.gnmap
├── nmap-services.nmap      # Detailed service detection on open ports
├── nmap-services.xml
└── nmap-services.gnmap

IMPORTANT: Always save nmap output to an organized directory structure. By default, use ./nmap-output/ or specify a custom directory.

Default Scanning Strategy

IMPORTANT: Unless the user explicitly requests a different scan type, ALWAYS use this two-phase approach:

Phase 1: Fast Port Discovery (Root SYN Scan)

sudo nmap -p- <target> -oA <output-dir>/nmap-portscan
  • Why sudo: Running as root enables fast SYN scan (-sS is implicit)
  • Why -p-: Scans all 65535 ports quickly
  • Duration: Typically 1-3 minutes for SYN scan
  • Output: List of all open ports

Host Down Detection: If the scan output contains "Note: Host seems down", automatically retry with:

sudo nmap -p- -Pn <target> -oA <output-dir>/nmap-portscan
  • -Pn: Skip host discovery, treat host as online
  • Use this when firewalls block ping probes

Phase 2: Targeted Service Detection

After Phase 1 completes, parse the open ports and run:

nmap -p <OPEN_PORT_LIST> -sV -sC <target> -oA <output-dir>/nmap-services
  • -p <OPEN_PORT_LIST>: Only scan the ports found to be open (e.g., -p 23,80,443,554,8000)
  • -sV: Service version detection
  • -sC: Run default NSE scripts for additional enumeration
  • Duration: Usually 1-3 minutes since only scanning known open ports

Why This Strategy?

  1. Speed: Fast SYN scan finds all open ports in 1-3 minutes
  2. Thoroughness: Covers all 65535 ports, not just top 1000
  3. Efficiency: Service detection only runs on confirmed open ports
  4. Accuracy: Two-phase approach reduces false negatives

Parsing Open Ports

After Phase 1, extract open ports using:

# Extract open ports from .gnmap file
grep "Ports:" <output-dir>/nmap-portscan.gnmap | sed 's/.*Ports: //' | tr ',' '\n' | grep '/open/' | cut -d'/' -f1 | tr -d ' ' | tr '\n' ',' | sed 's/,$//'

Or parse from .nmap file (matches the STATE column exactly, so open|filtered ports are excluded):

awk '$2=="open"{split($1,p,"/"); ports=ports sep p[1]; sep=","} END{print ports}' <output-dir>/nmap-portscan.nmap

Implementation Workflow

When the nmap-scan skill is invoked:

  1. Create output directory

    OUTPUT_DIR="./nmap-output"
    mkdir -p "$OUTPUT_DIR"
    
  2. Run Phase 1: Fast port discovery

    sudo nmap -p- <target> -oA "$OUTPUT_DIR/nmap-portscan"
    
  3. Check for "Host seems down" error

    if grep -q "Host seems down" "$OUTPUT_DIR/nmap-portscan.nmap"; then
        echo "Host appears down, retrying with -Pn flag..."
        sudo nmap -p- -Pn <target> -oA "$OUTPUT_DIR/nmap-portscan"
    fi
    
  4. Parse open ports from results

    OPEN_PORTS=$(awk '$2=="open"{split($1,p,"/"); ports=ports sep p[1]; sep=","} END{print ports}' "$OUTPUT_DIR/nmap-portscan.nmap")
    
  5. Run Phase 2: Service detection on open ports

    if [ -n "$OPEN_PORTS" ]; then
        nmap -p "$OPEN_PORTS" -sV -sC <target> -oA "$OUTPUT_DIR/nmap-services"
    else
        echo "No open ports found, skipping service detection."
    fi
    
  6. Report results location

    echo "Scan complete. Results saved to: $OUTPUT_DIR"
    

Scan Types

Quick Scan (Top 1000 Ports)

Use for initial reconnaissance, when time is limited, or only when the user explicitly requests a quick/fast scan instead of the default two-phase strategy:

nmap -sV -sC <target> -oA <output-prefix>
  • -sV: Service version detection
  • -sC: Run default NSE scripts
  • -oA: Output in all formats (normal, XML, grepable)
  • Scans top 1000 most common ports
  • Typical duration: 1-3 minutes
  • Limitation: May miss services on non-standard ports

Comprehensive Scan (All Ports)

Use for thorough assessment when all ports must be checked:

nmap -sV -sC -p- <target> -oA <output-prefix>
  • -p-: Scan all 65535 ports
  • Significantly longer duration (5-30+ minutes depending on target)
  • Use only when comprehensive coverage is required

Stealth SYN Scan

Use when trying to avoid detection (requires root/sudo):

sudo nmap -sS -sV -sC <target> -oA <output-prefix>
  • -sS: SYN stealth scan (doesn't complete TCP handshake)
  • Less likely to be logged by target
  • Requires root privileges

UDP Scan

Use when UDP services need to be enumerated:

sudo nmap -sU --top-ports 100 <target> -oA <output-prefix>
  • -sU: UDP scan
  • --top-ports 100: Scan top 100 UDP ports (UDP scanning is slow)
  • Common UDP services: DNS (53), SNMP (161), DHCP (67/68)
  • Very slow - use top-ports to limit scope

Aggressive Scan

Use for maximum information gathering (noisy):

nmap -A -T4 <target> -oA <output-prefix>
  • -A: Enable OS detection, version detection, script scanning, traceroute
  • -T4: Aggressive timing template (faster but more detectable)
  • Very noisy - will be detected by IDS/IPS
  • Use only with authorization

Vulnerability Scan

Use to check for known vulnerabilities:

nmap -sV --script vuln <target> -oA <output-prefix>
  • --script vuln: Run NSE vulnerability detection scripts
  • Checks for common CVEs and misconfigurations
  • Can be noisy and trigger alerts

OS Detection

Use to identify operating system:

sudo nmap -O <target> -oA <output-prefix>
  • -O: Enable OS detection
  • Requires root privileges
  • Uses TCP/IP stack fingerprinting

Scan Workflow

Default Workflow (Two-Phase Strategy)

Run Phase 1 (port discovery) and Phase 2 (service detection) per the Default Scanning Strategy and Implementation Workflow sections above. Then analyze:

Phase 3: Analysis

  • Review the service detection results to determine:
    • What services are running?
    • What versions are detected?
    • Are there any interesting services (web, SSH, database, IoT protocols)?
    • Do NSE scripts reveal any issues?

Additional Targeted Scans (Optional)

Based on service detection results, run specialized scans:

If web services found (80, 443, 8080, etc.):

nmap -p 80,443,8080,8443 --script http-* <target> -oA <output-dir>/nmap-web

If SSH found:

nmap -p 22 --script ssh-* <target> -oA <output-dir>/nmap-ssh

If RTSP found (554):

nmap -p 554 --script rtsp-* <target> -oA <output-dir>/nmap-rtsp

If ONVIF/camera suspected:

nmap -p 80,554,8000,8080 --script http-methods,http-headers <target> -oA <output-dir>/nmap-onvif

Output Management

Output Formats

Always use -oA <prefix> to generate all three formats:

  • .nmap - Normal human-readable format
  • .xml - XML format for parsing/importing into tools
  • .gnmap - Grepable format for command-line processing

Timing and Performance

Timing Templates

Use -T<0-5> to control scan speed:

  • -T0 (Paranoid): Extremely slow, for IDS evasion
  • -T1 (Sneaky): Very slow, for IDS evasion
  • -T2 (Polite): Slow, less bandwidth intensive
  • -T3 (Normal): Default, balanced speed
  • -T4 (Aggressive): Fast, recommended for modern networks
  • -T5 (Insane): Very fast, may miss results

Default: Use -T3 or omit (default is T3) Fast scans: Use -T4 when speed is important and network can handle it Stealth: Use -T1 or -T2 for evasion

Timeout Considerations

  • Phase 1 Port Discovery (sudo nmap -p-): 180-300 seconds timeout (3-5 minutes)
  • Phase 2 Service Detection (nmap -p <ports> -sV -sC): 120-180 seconds timeout (2-3 minutes)
  • UDP scan: 600+ seconds timeout (very slow)

Network Ranges

Single Host

nmap <ip-address>

CIDR Notation

nmap 192.168.1.0/24

IP Range

nmap 192.168.1.1-254

Multiple Hosts

nmap 192.168.1.1 192.168.1.10 192.168.1.100

Exclude Hosts

nmap 192.168.1.0/24 --exclude 192.168.1.1,192.168.1.254

NSE Scripts

Common Script Categories

# Authentication scripts
nmap --script auth <target>

# Brute force scripts
nmap --script brute <target>

# Default safe scripts
nmap -sC <target>  # equivalent to --script default

# Discovery scripts
nmap --script discovery <target>

# Vulnerability scripts
nmap --script vuln <target>

# All HTTP scripts
nmap --script "http-*" <target>

IoT-Specific Scripts

# RTSP enumeration
nmap -p 554 --script rtsp-methods,rtsp-url-brute <target>

# UPnP discovery
nmap -p 1900 --script upnp-info <target>

# MQTT discovery
nmap -p 1883,8883 --script mqtt-subscribe <target>

# Modbus enumeration
nmap -p 502 --script modbus-discover <target>

Result Analysis

Key Information to Extract

  1. Open Ports and Services

    • What ports are open?
    • What services are running?
    • What versions are detected?
  2. Service Fingerprints

    • Does version detection reveal outdated software?
    • Are there known vulnerabilities for detected versions?
  3. NSE Script Results

    • Authentication issues?
    • Information disclosure?
    • Misconfigurations?
  4. Operating System

    • What OS is running?
    • What OS version?

Parsing Nmap Output

Extract open ports:

grep "^[0-9]" nmap-output.nmap | grep "open"

Extract service versions:

grep -E "^[0-9]+/tcp.*open" nmap-output.nmap

Check for vulnerabilities in NSE output:

grep -i "vuln\|cve\|exploit" nmap-output.nmap

Common IoT Service Ports

When scanning IoT devices, pay special attention to:

PortServiceDescription

Content truncated.

When not to use it

  • When scanning sensitive networks without authorization
  • For small, single-port verification tasks where a simple curl suffices

Prerequisites

Sudo privilegesnmap

Limitations

  • Requires elevated permissions for optimal speed (SYN scan)
  • Cannot guarantee accuracy if target environment utilizes modern IDS

How it compares

Enforces a strict directory structure and a standard two-phase workflow to ensure reproducible security findings.

Compared to similar skills

nmap side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
nmap (this skill)12moReviewIntermediate
reverse-engineering-tools734moNo flagsAdvanced
game-hacking-techniques422moNo flagsAdvanced
solidity-security152moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

More by BrownFineSecurity

View all by BrownFineSecurity

apktool

BrownFineSecurity

Android APK unpacking and resource extraction tool for reverse engineering. Use when you need to decode APK files, extract resources, examine AndroidManifest.xml, analyze smali code, or repackage modified APKs.

713

ffind

BrownFineSecurity

Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.

16

iotnet

BrownFineSecurity

IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices.

10

jadx

BrownFineSecurity

Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.

116

logicmso

BrownFineSecurity

Analyze digital and analog captures from Saleae Logic MSO devices. Decode protocols like UART, SPI, I2C from exported binary files. Use when analyzing logic analyzer captures for CTF challenges, hardware reverse engineering, or protocol decoding.

12

netflows

BrownFineSecurity

Network flow extractor that analyzes pcap/pcapng files to identify outbound connections with automatic DNS hostname resolution. Use when you need to enumerate network destinations, identify what hosts a device communicates with, or map IP addresses to hostnames from packet captures.

18

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

Search skills

Search the agent skills registry