Run an Authorized Nmap Asset Discovery
An accurate asset inventory helps defenders find unknown devices and confirm that expected services are exposed. Nmap can support that work, but even routine scans create network traffic and can trigger monitoring or affect fragile systems.
Use these commands only for networks and systems you are explicitly authorized to assess. Confirm the target list, scan window, rate limits, and escalation contact with the network owner before starting.
Step 1: Define and Record the Approved Scope
Set the Target from the Written Scope
AuthorizationReplace the documentation-only example address below with the exact approved CIDR or host list from the engagement record. Keep scope in a variable so each command uses the same reviewed target. Do not widen the range to adjacent networks.
# Documentation range only: replace after confirming written authorization.TARGET_CIDR="192.0.2.0/24"printf 'Approved target: %s\n' "$TARGET_CIDR"nmap --version⯠View Expected Console Output
Approved target: 192.0.2.0/24Nmap version 7.x ...Step 2: Discover Responding Hosts Conservatively
Run Host Discovery and Save the Results
Low-Impact DiscoveryA host-discovery scan checks which addresses respond using probes selected by Nmap and the privileges available. Firewalls can suppress replies, so an empty result does not prove that an address is unused. Use a low scan rate and the approved maintenance window.
nmap -sn -T2 --reason -oA discovery "$TARGET_CIDR"⯠View Expected Console Output
Nmap scan report for host-a.example (192.0.2.15)Host is up, received echo-reply ...Nmap done: 256 IP addresses ...
Figure 1: A low-rate Nmap host-discovery run reports responding hosts only within the documentation range.
Step 3: Check a Small, Approved Service Set
Limit Service Detection to Approved Hosts
Service InventoryChoose only the hosts and ports listed in the approved plan. This example checks the top 20 ports with a TCP connect scan and light version detection. It does not run scripts or exploit checks; coordinate separately before any broader assessment.
# Example documentation address; replace with an approved host.TARGET_HOST="192.0.2.15"nmap -sT -sV --version-light --top-ports 20 -T2 \ --reason -oA service-review "$TARGET_HOST"⯠View Expected Console Output
PORT STATE SERVICE VERSION22/tcp open ssh OpenSSH ...443/tcp open https ...Step 4: Review, Store, and Reconcile the Inventory
Compare Findings with the Asset Register
Defensive Follow-UpKeep all three output formats with the scan record. Reconcile responding addresses and observed services against the CMDB or cloud inventory, then assign unknown assets and unexpected listeners to the responsible team for validation.
ls -l discovery.nmap discovery.gnmap discovery.xml \ service-review.nmap service-review.gnmap service-review.xmlsha256sum discovery.* service-review.* > scan-output.sha256sha256sum --check scan-output.sha256⯠View Expected Console Output
discovery.nmap: OKdiscovery.gnmap: OKdiscovery.xml: OKservice-review.nmap: OKservice-review.gnmap: OKservice-review.xml: OK