Recon & Port Scanning cheatsheet
11 copy-paste commands for recon & port scanning in CTFs and OSCP-style labs. Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Fast SYN Scan (Top 1000 Ports)
Speedy initial discovery of open TCP ports with version detection and default safe scripts.
nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}nmapreconscantcp
All-Port TCP Exhaustive Scan
Scan all 65,535 TCP ports at a high packet rate, saving output to all formats.
nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}nmapall-portsreconfull
Top UDP Service Discovery Scan
Quick scan of the most common 20 UDP ports (SNMP, TFTP, DNS, NTP, DHCP).
sudo nmap -sU --top-ports 20 -Pn --open -oN nmap_udp.txt {TARGET_IP}nmapudpsnmprecon
Nmap NSE Vulnerability Audit Scripts
Run all Nmap Vuln & Exploit category scripts against active discovered ports.
nmap --script "vuln and safe" -Pn -oN nmap_vuln.txt {TARGET_IP}nmapnsecvevuln
RustScan Ultra-Fast Port Detection
Fast asynchronous port scanner piping discovered open ports directly into detailed Nmap.
rustscan -a {TARGET_IP} -r 1-65535 --ulimit 5000 -- -sC -sV -oN rustscan.txtrustscanfastrecon
Masscan High-Rate Subnet Sweeper
Blazing fast raw packet scanner across entire target subnet on default interface.
sudo masscan -p1-65535 {TARGET_IP}/24 --rate=5000 -e {INTERFACE} -oL masscan.txtmasscanreconcidr
SNMPwalk v2c Community Enumeration
Query SNMP management information base using default public community string.
snmpwalk -v 2c -c public {TARGET_IP}snmpreconudp
onesixtyone SNMP Community String Brute
Rapidly brute-force SNMP community strings from wordlist against target host.
onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt {TARGET_IP}snmpbruteforcerecon
rpcclient Anonymous / Null Session User Enum
Establish null session to RPC endpoint and list domain users, groups, and password policy.
rpcclient -U "" -N {TARGET_IP} -c "enumdomusers; querydispinfo; enumdomgroups"rpcnull-sessionsmbactive-directory
SMBMap Anonymous / Guest Share Check
Check SMB permissions across all shares anonymously without credentials.
smbmap -H {TARGET_IP} -u "" -p ""smbsmbmapsharesrecon
DNS Zone Transfer (AXFR) Audit
Attempt full DNS zone transfer from target nameserver to expose all subdomains.
dig axfr @{TARGET_IP} {DOMAIN}dnsaxfrzone-transferrecon
Use these commands with your values filled in. ZeroBox interpolates target IP, domain and credentials into every command. Open the cheatsheet