Nmap Command Builder
Build an Nmap command for an authorised scan of your own infrastructure, with the scan type, port selection, service detection, timing and output options explained.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Scan only what you are authorised to scan
Port scanning infrastructure you do not own or have written permission to test is unlawful in many jurisdictions and is a violation of terms of service almost everywhere else. This builder is for auditing your own estate: verifying that a firewall change took effect, confirming a decommissioned service is actually gone, checking what a newly provisioned host exposes, or producing evidence for an internal review. Establish the authorisation before the command, not after.
Scan type determines what you learn and what you disturb
A TCP connect scan completes the handshake and is reliable but appears in every application log. A SYN scan sends only the first packet and is faster and quieter, and requires elevated privileges. A UDP scan is slow and unreliable by nature, because a closed UDP port may return nothing at all, which is indistinguishable from a filtered one; a UDP scan of the full range on a single host can take hours and is usually the wrong tool.
Timing is where scans go wrong
The aggressive templates send packets fast enough to trip intrusion detection, exhaust connection tables on small appliances, and occasionally knock over embedded devices that were never designed for concurrent connections. Printers, industrial controllers, IP cameras and older network hardware are all documented casualties of enthusiastic scanning. On production networks the polite templates are not merely courteous, they are how you avoid causing the outage you were trying to prevent.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Is port scanning legal?
Scanning systems you own or have explicit written authorisation to test is legal and routine. Scanning third party systems without permission is unlawful in many jurisdictions, including under the Computer Misuse Act and the Computer Fraud and Abuse Act. Get authorisation in writing first.
What is the difference between -sS and -sT?
A SYN scan sends only the opening packet and never completes the handshake, which is faster and leaves less in application logs, but it requires root or an equivalent capability. A connect scan completes the handshake using the normal socket API and works unprivileged, at the cost of being noisier and slower.
Why is UDP scanning so slow?
Because a closed UDP port often returns nothing rather than an error, so Nmap must wait for a timeout on every unanswered port and retransmit. Rate limiting of ICMP unreachable messages makes it slower still. Scan a targeted list of UDP ports rather than the full range.
Can a scan break things?
Yes. Aggressive timing has knocked over printers, industrial controllers, IP cameras and older network appliances, and version detection sends probes that some services handle badly. On production networks use polite timing and exclude fragile devices explicitly.
What is the safest way to verify a firewall change?
A targeted scan of the specific ports you changed, from the network segment the rule applies to, with polite timing. Scanning the full range from the wrong segment tells you very little and takes much longer.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose your scan objective and targets to get the Nmap command with each flag explained.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.