Nmap ホスト探索とポートスキャンでは、controlled/documented workflow で live host と exposed service を mapping します。4 guided lab で discovery、TCP/UDP scan、performance、output format を扱い、challenge で simulated black-box subnet を調査します。
lab は localhost、challenge は Web、Redis、DNS を持つ isolated Docker network を使います。host presence と service exposure を区別し、結果を保存します。
学習内容
-sn、ARP、ICMP で port scan なしに host discovery- TCP Connect、half-open SYN、UDP scan の比較
- open、closed、filtered、
open|filteredの解釈 - timing、top ports、specific port/range で scope 制限
- Normal、Grepable、XML output の保存
- shell で Grepable output から open service host を抽出
- attached subnet、host list、TCP/UDP result の統合
このコースの対象者
Junior pentester、network defender、administrator、Nmap 学習者向けです。exploitation/fingerprinting は扱いません。
前提知識: Linux shell、IPv4 subnet、TCP/UDP port、ICMP、client-server networking、authorized scope。
学習環境: Ubuntu 22.04 VM の 5 activity(4 guided lab、1 challenge)。local Python service と Nginx/Redis/DNS を持つ 172.18.0.0/24 Docker network を使用します。
よくある質問
public/third-party system を scan しますか?
いいえ。localhost と private Docker subnet のみです。外部では明示的な許可が必要です。
SYN scan は見えませんか?
いいえ。handshake は完了しませんが sensor、firewall、capture で検知できます。
SYN、ARP、UDP に sudo が必要なのはなぜですか?
raw packet access が必要です。TCP Connect は通常 socket を使います。
open port は vulnerability の証明ですか?
いいえ。reachable service を示すだけで追加分析が必要です。





