Nmap Host Discovery & Port Scanning teaches you to map live hosts and exposed services with a controlled, evidence-preserving workflow. Four guided labs cover host discovery, TCP and UDP scan mechanics, performance choices, and output formats; a final challenge asks you to map a simulated black-box subnet independently.
The guided work targets localhost services, while the challenge provides an isolated Docker network with web, Redis, and DNS hosts. You learn to separate host presence from service exposure, tune scope before speed, and produce scan artifacts that humans and command-line tools can review.
What You Will Learn
- Discover live hosts without port scanning by using
-sn, ARP, and ICMP probes - Compare full TCP Connect, half-open SYN, and connectionless UDP scan behavior
- Interpret open, closed, filtered, and
open|filteredresults without equating exposure with vulnerability - Limit scans with timing templates, top-port counts, explicit ports, and narrow ranges
- Save Nmap results in Normal, Grepable, and XML formats for review and automation
- Parse Grepable output with shell tools to extract hosts with open services
- Inspect an attached subnet, scan discovered hosts from a list, and consolidate TCP/UDP findings
Who This Course Is For
This course is for junior penetration testers, network defenders, system administrators, and security learners who want practical Nmap fundamentals. It focuses on discovery and service enumeration, not vulnerability exploitation or service fingerprinting.
Prerequisites: Basic Linux shell use, IPv4 subnets, TCP/UDP ports, ICMP, and client-server networking. Familiarity with authorized security-assessment scope is essential.
Learning environment: Five independent activities in browser-accessible Ubuntu 22.04 virtual machines: four guided labs and one challenge. Local Python services support the labs, and a dedicated 172.18.0.0/24 Docker network provides simulated Nginx, Redis, and DNS targets for the challenge.
Frequently Asked Questions
Will the exercises scan public or third-party systems?
No. Guided scans use localhost, and the challenge uses a private Docker subnet created inside the training VM. Apply Nmap elsewhere only to systems you own or are explicitly authorized to assess.
Does a SYN scan make me invisible to defenders?
No. It avoids completing the TCP handshake and may reduce application-level logging, but network sensors, firewalls, and packet captures can still detect it. “Stealth” describes scan mechanics, not guaranteed invisibility.
Why do SYN, ARP, and UDP scans use sudo?
They require raw-packet or low-level network access. TCP Connect scans can use the operating system’s normal socket API without those privileges, which is one reason the course compares the methods.
Does an open port prove that a host is vulnerable?
No. It indicates a reachable service boundary. Determining the service, version, configuration, and actual weakness requires additional authorized analysis beyond this course.





