> For the complete documentation index, see [llms.txt](https://personal-archive.gitbook.io/oscp-exam-prep/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://personal-archive.gitbook.io/oscp-exam-prep/commons/basic-scans.md).

# Basic Scans

## Nmap

1. Network Scan

{% code overflow="wrap" fullWidth="true" %}

```
sudo nmap <IP>/<subnet mask> -o network.nmap
```

{% endcode %}

2. Port Scan

<pre data-overflow="wrap" data-full-width="true"><code><strong>sudo nmap --top-ports=100 &#x3C;IP> -Pn -o target.openmap
</strong><strong>sudo nmap -p- --open &#x3C;IP> -Pn -o target.nmap
</strong><strong>
</strong>sudo nmap -sV -sC -sT -T4 -A --top-ports=100 --open &#x3C;IP> -Pn -o target.fullmap
sudo nmap -sV -sC -sT -T4 -A -p- --open &#x3C;IP> -Pn -o target.fullmap
sudo nmap -sS -vv -T4 -A -p- --open &#x3C;IP> -Pn -o nmap.fullmap

#S1ren nmap scan
sudo nmap -sV -sC -sT -T4 -A -p&#x3C;> --open &#x3C;IP> -Pn -o target.map&#x3C;>

sudo nmap -sV -sC -sU -T4 -A --top-ports=100 &#x3C;IP> -Pn -o target.udpmap
sudo nmap -sV -sC -sU -T4 -A -p- --open &#x3C;IP> -Pn -o target.udpmap
</code></pre>

3. Vulnerability Scan

{% code overflow="wrap" fullWidth="true" %}

```
sudo nmap -sV -p<> --script "vuln" <IP>
```

{% endcode %}

3. UDP Scan

{% code overflow="wrap" fullWidth="true" %}

```
sudo nmap -sU --top-ports 100 -vvv <IP> -o target.udp
```

{% endcode %}

4. S1REN Scan

{% code overflow="wrap" fullWidth="true" %}

```
sudo nmap -sC -sV -p- -n -Pn --open --min-rate 2000 <IP> -o target.s1ren
```

{% endcode %}

## Alternative: AutoRecon

{% code overflow="wrap" fullWidth="true" %}

```
sudo autorecon <IP>
```

{% endcode %}
