Skip to content

Run an Authorized Nmap Asset Discovery

An accurate asset inventory helps defenders find unknown devices and confirm that expected services are exposed. Nmap can support that work, but even routine scans create network traffic and can trigger monitoring or affect fragile systems.

Use these commands only for networks and systems you are explicitly authorized to assess. Confirm the target list, scan window, rate limits, and escalation contact with the network owner before starting.


Step 1: Define and Record the Approved Scope

01

Set the Target from the Written Scope

Authorization

Replace the documentation-only example address below with the exact approved CIDR or host list from the engagement record. Keep scope in a variable so each command uses the same reviewed target. Do not widen the range to adjacent networks.

Terminal window
# Documentation range only: replace after confirming written authorization.
TARGET_CIDR="192.0.2.0/24"
printf 'Approved target: %s\n' "$TARGET_CIDR"
nmap --version
❯ View Expected Console Output
Approved target: 192.0.2.0/24
Nmap version 7.x ...

Step 2: Discover Responding Hosts Conservatively

02

Run Host Discovery and Save the Results

Low-Impact Discovery

A host-discovery scan checks which addresses respond using probes selected by Nmap and the privileges available. Firewalls can suppress replies, so an empty result does not prove that an address is unused. Use a low scan rate and the approved maintenance window.

Terminal window
nmap -sn -T2 --reason -oA discovery "$TARGET_CIDR"
❯ View Expected Console Output
Nmap scan report for host-a.example (192.0.2.15)
Host is up, received echo-reply ...
Nmap done: 256 IP addresses ...
Nmap low-rate host discovery results limited to the documentation-only 192.0.2.0/24 range

Figure 1: A low-rate Nmap host-discovery run reports responding hosts only within the documentation range.


Step 3: Check a Small, Approved Service Set

03

Limit Service Detection to Approved Hosts

Service Inventory

Choose only the hosts and ports listed in the approved plan. This example checks the top 20 ports with a TCP connect scan and light version detection. It does not run scripts or exploit checks; coordinate separately before any broader assessment.

Terminal window
# Example documentation address; replace with an approved host.
TARGET_HOST="192.0.2.15"
nmap -sT -sV --version-light --top-ports 20 -T2 \
--reason -oA service-review "$TARGET_HOST"
❯ View Expected Console Output
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH ...
443/tcp open https ...

Step 4: Review, Store, and Reconcile the Inventory

04

Compare Findings with the Asset Register

Defensive Follow-Up

Keep all three output formats with the scan record. Reconcile responding addresses and observed services against the CMDB or cloud inventory, then assign unknown assets and unexpected listeners to the responsible team for validation.

Terminal window
ls -l discovery.nmap discovery.gnmap discovery.xml \
service-review.nmap service-review.gnmap service-review.xml
sha256sum discovery.* service-review.* > scan-output.sha256
sha256sum --check scan-output.sha256
❯ View Expected Console Output
discovery.nmap: OK
discovery.gnmap: OK
discovery.xml: OK
service-review.nmap: OK
service-review.gnmap: OK
service-review.xml: OK

Comments