Overview
Nmap discovers live hosts, enumerates open ports and identifies the software answering on them, with optional NSE scripts for everything from HTTP enumeration to vulnerability checks.\nDefenders use it for authorised asset discovery and drift detection; attackers use the identical command for reconnaissance.\nKnowing what Nmap reports about your own perimeter is the fastest way to learn what a stranger sees.
Indicators of Compromise
Signals that suggest this is present on a system.
- SYN scans against many ports from one source
- NSE script traffic hitting HTTP and SMB paths
- Unusual service probes immediately after a host appears