Nmap app icon

Files and network

Nmap

Install Nmap for Windows to discover hosts, scan ports, identify services and run the bundled scripting engine from a command line or the Zenmap GUI.

WindowsmacOSLinuxNPSL

The reference network scanner, from host discovery to NSE scripting

Nmap is the tool that defined what a network scanner is. It answers a deceptively simple question - which machines are reachable, and what is listening on them - and it answers it with a depth that has kept it relevant for more than two decades. A single run can discover live hosts on a range, probe a thousand TCP ports, send payloads to learn which service and version answered, guess the operating system from the shape of its responses, and hand the results to a scripting engine for further checks. The Windows package wraps all of this in a self-installer that also delivers the Npcap capture driver, the Zenmap graphical front end and the Ncat utility.

The scanning workflow

Most work starts with a target - a hostname, an address, a range or a CIDR block - and the default scan of the most common thousand TCP ports. From there the options accumulate. Port selection narrows or widens the set, including all 65535 ports when thoroughness matters more than time. Scan type decides how the probes are built: a SYN scan is fast and quiet on the wire but needs raw-packet privileges, while a connect scan uses the operating system's own networking calls and works without them. UDP scanning is the slow, patient corner of the tool, because an open UDP port often says nothing at all and the scanner must wait for timeouts before deciding. Version detection, enabled with the -sV option, sends service-specific probes and compares replies against a large signature database. Operating system detection uses a separate set of crafted probes. Beyond those, the Nmap Scripting Engine runs Lua scripts for tasks such as certificate inspection, service enumeration and default-credential checks. Output can be human-readable, greppable or XML, and the XML is what most other tools consume. Zenmap offers the same engine through a graphical interface with saved profiles and topology views, while Ncat and Ndiff cover ad-hoc connections and comparison of two scans.

Practical settings, limits and the license

Scanning is a timing problem as much as a technical one. Aggressive timing templates finish sooner but lose accuracy on congested or filtered links, and defensive devices may rate-limit or block a fast scanner, so results on a protected network are best treated as evidence to be confirmed rather than a verdict. UDP scans commonly need retries, and firewall drops look identical to closed ports. On Windows, raw scans and OS detection require administrator rights and the bundled Npcap driver; without elevation, Nmap falls back to connect scans. One point that deserves plain language: Nmap is not released under the GPL. Its source is governed by the Nmap Public Source License, which is derived from the GNU GPL version 2 but adds its own terms and conditions, and the project offers separate commercial and OEM licensing for organisations that need different redistribution rights. Anyone planning to redistribute the installer or a modified build should read the license text rather than assume the usual GPL permissions apply. Finally, scanning systems you do not own or have written permission to test is unlawful in many jurisdictions, and the tool makes no attempt to hide that it has been used.

Where something else fits better

For internet-scale sweeps, masscan and zmap trade Nmap's depth for raw speed. For passive visibility, tools such as Zeek observe traffic instead of generating it. For continuous vulnerability management with dashboards and reporting, a commercial platform is the practical choice. Nmap remains the right answer when you need accurate, deeply inspectable results on a bounded set of targets.

Best for
Administrators, auditors and security practitioners who need accurate host discovery, port and service identification, OS fingerprinting and scriptable checks on networks they are authorised to test.
Good to know
Nmap is licensed under the Nmap Public Source License, derived from the GPL v2 but with additional terms, not the GPL itself. Raw scans and OS detection need administrator rights and the bundled Npcap driver.

Nmap reports what is alive on a network and what each live host is offering.

How to get started

  1. Run the official installer and keep the Npcap driver selected; raw scanning and OS detection depend on it.
  2. Open a terminal as administrator and scan a target you are authorised to test, for example a single address, before widening to a range.
  3. Ask for more than open ports: version detection identifies the service behind a port, and a default script run adds safe enumeration checks.
  4. Save every scan in XML so results can be compared later with Ndiff instead of being re-run from memory.

Keep timing conservative on production networks: a fast scan whose output you cannot trust is worth less.

Questions & answers

Is Nmap free software?

It is free to download and use, but its license is not the GPL. Nmap uses the Nmap Public Source License, derived from the GPL version 2 with additional terms.

Do I need administrator rights on Windows?

For SYN scans, OS detection and most packet-crafting features, yes, along with the Npcap driver the installer offers. Without elevation Nmap can still run connect scans against TCP ports.

Can I scan any network I like?

No. Port scanning systems without authorisation is illegal in many countries and may breach provider terms. Scan only hosts you own or have written permission to test.

More in files and network

View category