Security

Nmap Command Builder

Build an Nmap command for an authorised scan of your own infrastructure, with the scan type, port selection, service detection, timing and output options explained.

Last reviewed by the Radiatus Cloud team

Use this only against systems you own or have written authorisation to test. Unauthorised scanning is unlawful in many jurisdictions.
Command appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Scan only what you are authorised to scan

Port scanning infrastructure you do not own or have written permission to test is unlawful in many jurisdictions and is a violation of terms of service almost everywhere else. This builder is for auditing your own estate: verifying that a firewall change took effect, confirming a decommissioned service is actually gone, checking what a newly provisioned host exposes, or producing evidence for an internal review. Establish the authorisation before the command, not after.

Scan type determines what you learn and what you disturb

A TCP connect scan completes the handshake and is reliable but appears in every application log. A SYN scan sends only the first packet and is faster and quieter, and requires elevated privileges. A UDP scan is slow and unreliable by nature, because a closed UDP port may return nothing at all, which is indistinguishable from a filtered one; a UDP scan of the full range on a single host can take hours and is usually the wrong tool.

Timing is where scans go wrong

The aggressive templates send packets fast enough to trip intrusion detection, exhaust connection tables on small appliances, and occasionally knock over embedded devices that were never designed for concurrent connections. Printers, industrial controllers, IP cameras and older network hardware are all documented casualties of enthusiastic scanning. On production networks the polite templates are not merely courteous, they are how you avoid causing the outage you were trying to prevent.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Is port scanning legal?

Scanning systems you own or have explicit written authorisation to test is legal and routine. Scanning third party systems without permission is unlawful in many jurisdictions, including under the Computer Misuse Act and the Computer Fraud and Abuse Act. Get authorisation in writing first.

What is the difference between -sS and -sT?

A SYN scan sends only the opening packet and never completes the handshake, which is faster and leaves less in application logs, but it requires root or an equivalent capability. A connect scan completes the handshake using the normal socket API and works unprivileged, at the cost of being noisier and slower.

Why is UDP scanning so slow?

Because a closed UDP port often returns nothing rather than an error, so Nmap must wait for a timeout on every unanswered port and retransmit. Rate limiting of ICMP unreachable messages makes it slower still. Scan a targeted list of UDP ports rather than the full range.

Can a scan break things?

Yes. Aggressive timing has knocked over printers, industrial controllers, IP cameras and older network appliances, and version detection sends probes that some services handle badly. On production networks use polite timing and exclude fragile devices explicitly.

What is the safest way to verify a firewall change?

A targeted scan of the specific ports you changed, from the network segment the rule applies to, with polite timing. Scanning the full range from the wrong segment tells you very little and takes much longer.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose your scan objective and targets to get the Nmap command with each flag explained.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.