Operator tip · nmap

Host discovery first

On a flat lab net: nmap -sn 10.10.0.0/24 then target live hosts. Skip -Pn until you know ICMP is blocked.

easy reconnmapdiscovery
/nmap/ · /tips/nmap-host-discovery/

Guide

Spraying a full port scan across a /24 before you know who is alive burns time and fills logs with dead hosts. Discover first, then focus.

Why it matters

Host discovery (-sn) is cheap. A live list lets you prioritize, name hosts in notes, and avoid treating broadcast/gateway noise as targets. -Pn skips discovery and assumes every IP is up — useful when ICMP is filtered, wasteful when it is not.

How-to

# Ping sweep (no port scan)
nmap -sn 10.10.0.0/24 -oG - | awk '/Up$/{print $2}'

# Then deep-scan only live hosts
nmap -sC -sV -p- -iL live.txt -oA recon/live

Examples

nmap -sn 10.10.11.0/24
# Up hosts → write live.txt → targeted -sC -sV