[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fStmfzBQfyc3eHwnLuWe_9Tcoy8qNyUP4qzMeS9Kc0w8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},184,"What is the Nmap zip version for Windows and how is it configured?","Nmap provides a command-line zip version for Windows, downloadable from the official Nmap site. After extracting the zip, it can be used directly from the command line without a full installation, provided WinPcap is installed (or set up as described in the article). This allows penetration testers to leverage Nmap's powerful scanning capabilities on a Windows pivot machine. For related techniques on Windows, see [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries).","\u003Cp>Nmap provides a command-line zip version for Windows, downloadable from the official Nmap site. After extracting the zip, it can be used directly from the command line without a full installation, provided WinPcap is installed (or set up as described in the article). This allows penetration testers to leverage Nmap&#39;s powerful scanning capabilities on a Windows pivot machine. For related techniques on Windows, see [Penetration Techniques - Deleting Single Windows Log Entries](\u002Fnews\u002Fpenetration-techniques-deleting-single-windows-log-entries).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-running-masscan-and-nmap-on-windows-platform\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-nmap-zip-version-for-windows-and-how-is-it-configured-1777484811600","Nmap, Windows zip version, command-line scanning, WinPcap, pivot machine",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},47,"Penetration Techniques - Running Masscan and Nmap on Windows Platform","penetration-techniques-running-masscan-and-nmap-on-windows-platform","Learn how to compile Masscan, install WinPcap via command line, and use Masscan and Nmap on Windows for effective internal network penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In internal network penetration, information gathering is particularly important.\u003C\u002Fp>\u003Cp>Facing the complex environment of internal networks, although network scanning can easily expose oneself, scanning can discover information such as surviving hosts, open ports, running services, and operating systems within the internal network, laying the foundation for further penetration.\u003C\u002Fp>\u003Cp>When selecting scanning tools, one must consider not only functionality but also the applicability of the tools.\u003C\u002Fp>\u003Cp>In reality, the pivot machine is often not a Linux server and lacks a suitable environment to install Nmap, Zmap, and Masscan.\u003C\u002Fp>\u003Cp>In other words, which command-line scanning tools can be used directly under Windows?\u003C\u002Fp>\u003Cp>The well-known open-source scanning tools Nmap, Zmap, and Masscan each have their own unique features in terms of functionality.\u003C\u002Fp>\u003Cp>In terms of applicability, Zmap requires the installation of Cygwin to run on Windows, so it is not within the scope of consideration.\u003C\u002Fp>\u003Cp>Masscan supports compilation for the Windows platform, and Nmap provides a command-line version, making Masscan and Nmap appear to meet the requirements.\u003C\u002Fp>\u003Cp>However, both Masscan and Nmap require WinPcap support, meaning WinPcap must be installed before use.\u003C\u002Fp>\u003Cp>So, can WinPcap be installed via the command line?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article aims to address the above issues and introduces the following content:\u003C\u002Fp>\u003Cul>\u003Cli>Compiling Masscan on Windows Platform\u003C\u002Fli>\u003Cli>Installing WinPcap via Windows Command Line\u003C\u002Fli>\u003Cli>Introduction to Using Masscan\u003C\u002Fli>\u003Cli>Introduction to Configuring and Using Nmap\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Compiling Masscan on Windows Platform\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Masscan Download Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Frobertdavidgraham\u002Fmasscan\u002F\u003C\u002Fp>\u003Cp>Compilation Tool: vs2012\u003C\u002Fp>\u003Cp>The compilation options do not include configuration for vs2012, so direct compilation will result in errors\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add vs2012 configuration information in string_s.h\u003C\u002Fp>\u003Cp>Located in misc-string_s.h, add the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#if defined(_MSC_VER) &amp;&amp; (_MSC_VER == 1700)\u003Cbr>\u002F*Visual Studio 2012*\u002F\u003Cbr># include \u003Cstdio.h>\u003Cbr># include \u003Cstring.h>\u003Cbr># define strcasecmp     _stricmp\u003Cbr># define memcasecmp     _memicmp\u003Cbr># ifndef PRIu64\u003Cbr>#  define PRIu64 \"llu\"\u003Cbr>#  define PRId64 \"lld\"\u003Cbr>#  define PRIx64 \"llx\"\u003Cbr># endif\u003C\u002Fstring.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compilation successful, executing masscan.exe, prompts Packet.dll: not found\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019797369_0_6550627260.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Method to obtain Packet.dll:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing WinPcap, obtain it under System32\u003C\u002Fp>\u003Cp>\u003Cstrong>WinPcap download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.winpcap.org\u002Finstall\u002Fdefault.htm\u003C\u002Fp>\u003Cp>Install WinPcap on another system, locate Packet.dll and Wpcap.dll under System32, copy them to the same directory as masscan.exe on the test system, and run again\u003C\u002Fp>\u003Cp>The program starts normally but cannot scan, reporting the following error:\u003C\u002Fp>\u003Cp>`FAIL: Error opening adapter: The system cannot find the device specified. (20)\u003C\u002Fp>\u003Cp>adapter[\\Device\\NPF_{71D19B82-0818-4685-A8E7-A6C7C812F2EA}].init: failed`\u003C\u002Fp>\u003Cp>\u003Cstrong>Question: Does the test system also need to install WinPcap to use it?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After actual testing, indeed it does\u003C\u002Fp>\u003Ch2>0x03 Installing WinPcap via Windows Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Testing on a 32-bit system:\u003C\u002Fh3>\u003Cp>Using ProcessMonitor to monitor the WinPcap installation process (32-bit system), the following information was obtained:\u003C\u002Fp>\u003Cul>\u003Cli>Releases packet.dll and wpcap.dll in the \\system32\\ folder\u003C\u002Fli>\u003Cli>Releases npf.sys in \\system32\\drivers\\\u003C\u002Fli>\u003Cli>Installs the npf service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Obtain configuration information of the installed service npf through the sc command:\u003C\u002Fp>\u003Cp>sc qc npf\u003C\u002Fp>\u003Cp>Information obtained as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[SC] QueryServiceConfig SUCCESS\u003Cbr>\u003Cbr>SERVICE_NAME: npf\u003Cbr>        TYPE               : 1  KERNEL_DRIVER\u003Cbr>        START_TYPE         : 3   DEMAND_START\u003Cbr>        ERROR_CONTROL      : 1   NORMAL\u003Cbr>        BINARY_PATH_NAME   : system32\\drivers\\npf.sys\u003Cbr>        LOAD_ORDER_GROUP   :\u003Cbr>        TAG                : 0\u003Cbr>        DISPLAY_NAME       : NetGroup Packet Filter Driver\u003Cbr>        DEPENDENCIES       :\u003Cbr>        SERVICE_START_NAME :\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019807883_1_8c9aab43e0.jpeg\">\u003C\u002Fp>\u003Cp>View running status:\u003C\u002Fp>\u003Cp>sc query npf\u003C\u002Fp>\u003Cp>Information obtained is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SERVICE_NAME: npf\u003Cbr>        TYPE               : 1  KERNEL_DRIVER\u003Cbr>        STATE              : 4  RUNNING\u003Cbr>                                (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)\u003Cbr>        WIN32_EXIT_CODE    : 0  (0x0)\u003Cbr>        SERVICE_EXIT_CODE  : 0  (0x0)\u003Cbr>        CHECKPOINT         : 0x0\u003Cbr>        WAIT_HINT          : 0x0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019821455_2_43b9a79ccd.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding registry keys and values will be created, indicating service configuration information, location as follows:\u003C\u002Fp>\u003Cul>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\npf\u003C\u002Fli>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\npf\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019831687_3_e88ae2e0e4.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019846254_4_2ba688a421.jpeg\">\u003C\u002Fp>\u003Cp>It is speculated that as long as the above installation operations can be simulated, WinPcap can be installed via the command line.\u003C\u002Fp>\u003Cp>\u003Cstrong>The simulated installation operations are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Release files\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>copy packet.dll %SystemRoot%\\system32\\\u003C\u002Fp>\u003Cp>copy wpcap.dll %SystemRoot%\\system32\\\u003C\u002Fp>\u003Cp>copy npf.sys %SystemRoot%\\system32\\drivers\\`\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Create service\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>sc create npf binPath= system32\\drivers\\npf.sys type= kernel start= demand error= normal tag= no DisplayName= \"NetGroup Packet Filter Driver\"\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Start the service\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>sc start npf\u003C\u002Fp>\u003Cp>Test commands are as follows:\u003C\u002Fp>\u003Cp>masscan.exe -p80 192.168.81.143\u003C\u002Fp>\u003Cp>Successfully executed masscan.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019862534_5_8e94ea104a.jpeg\">\u003C\u002Fp>\u003Ch3>Test 64-bit system:\u003C\u002Fh3>\u003Cp>Using ProcessMonitor to monitor the WinPcap installation process (32-bit system), obtained the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Release 64-bit packet.dll and wpcap.dll in the \\system32\\ folder\u003C\u002Fli>\u003Cli>Release 64-bit npf.sys in the \\system32\\drivers\\ folder\u003C\u002Fli>\u003Cli>Release 32-bit packet.dll, wpcap.dll, and pthreadVC.dll in the \\syswow64\\ folder\u003C\u002Fli>\u003Cli>Install the npf service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Through actual testing and optimization, when executing 32-bit masscan.exe in a 64-bit environment, 64-bit packet.dll and wpcap.dll are not required, 32-bit pthreadVC.dll is not required, only the 64-bit driver npf.sys needs to be installed\u003C\u002Fp>\u003Cp>Moreover, whether on a 32-bit or 64-bit system, packet.dll and wpcap.dll can be placed in the same directory as masscan.exe (of course, since it is compiled with vs2012, msvcr110d.dll is also required)\u003C\u002Fp>\u003Cp>That is to say, for 32-bit and 64-bit systems, it is only necessary to copy different versions of npf.sys to the \\system32\\drivers\\ folder.\u003C\u002Fp>\u003Cp>Then create the service npf and install it, and the entire process is completed.\u003C\u002Fp>\u003Cp>Automate the above process through batch processing, the one-click installation script code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>@echo off\u003Cbr>cd %~dp0\u003Cbr>if \"%PROCESSOR_ARCHITECTURE%\"==\"x86\" move npf_x86.sys %SystemRoot%\\system32\\drivers\\npf.sys\u003Cbr>if \"%PROCESSOR_ARCHITECTURE%\"==\"AMD64\" move npf_x64.sys %SystemRoot%\\system32\\drivers\\npf.sys\u003Cbr>if exist %SystemRoot%\\system32\\drivers\\npf.sys (echo move success!) else (echo move error!)\u003Cbr>sc create npf binPath= system32\\drivers\\npf.sys type= kernel start= demand error= normal tag= no DisplayName= \"NetGroup Packet Filter Driver\"\u003Cbr>sc start npf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The relevant code and required dll files have been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Masscan Usage Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Scan specified network segment and ports:\u003C\u002Fp>\u003Cp>masscan.exe -p80 192.168.81.1\u002F24\u003C\u002Fp>\u003Cp>Found a server with port 80 open, response as follows:\u003C\u002Fp>\u003Cp>Discovered open port 80\u002Ftcp on 192.168.81.143\u003C\u002Fp>\u003Cp>Scan all open ports on the specified host:\u003C\u002Fp>\u003Cp>masscan.exe -p0-65535 192.168.81.143\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867320_6_a7a33d25f0.jpeg\">\u003C\u002Fp>\u003Cp>Scan specific ports on the specified host:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443 192.168.81.143\u003C\u002Fp>\u003Cp>Retrieve banners:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443,3306 192.168.81.143 --banners\u003C\u002Fp>\u003Cp>Start scan via configuration file:\u003C\u002Fp>\u003Cp>Save configuration information in 1.conf:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443,3306 192.168.81.143 --banners --echo&gt;1.conf\u003C\u002Fp>\u003Cp>Read configuration file 1.conf and start scan:\u003C\u002Fp>\u003Cp>masscan.exe -c 1.conf\u003C\u002Fp>\u003Cp>Modify scanning speed to 100,000 packets\u002Fsecond (maximum 300,000 packets\u002Fsecond on Windows), default is 100 packets\u002Fsecond:\u003C\u002Fp>\u003Cp>--rate 100000\u003C\u002Fp>\u003Cp>Output formats:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>-oX \u003Cfilespec> (XML)\u003Cbr>-oB \u003Cfilespec> (Binary)\u003Cbr>-oG \u003Cfilespec> (Grep)\u003Cbr>-oJ \u003Cfilespec> (Json)\u003Cbr>-oL \u003Cfilespec> (List)\u003Cbr>-oU \u003Cfilespec> (Unicornscan format)\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additionally, by default, masscan enables the following configurations:\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>-sS: this does SYN scan only (currently, will change in the future)\u003C\u002Fp>\u003Cp>-Pn: doesn't ping hosts first, which is fundamental to the async operation\u003C\u002Fp>\u003Cp>-n: no DNS resolution happens\u003C\u002Fp>\u003Cp>--randomize-hosts: scan completely randomized\u003C\u002Fp>\u003Cp>--send-eth: sends using raw libpcap\u003C\u002Fp>\u003Ch2>0x05 Nmap Configuration and Usage Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Nmap Zip Version Download Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnmap.org\u002Fdist\u002Fnmap-7.50-win32.zip\u003C\u002Fp>\u003Cp>Using Nmap also requires installing WinPcap in advance via command line\u003C\u002Fp>\u003Cp>Also add vs2013 dlls: msvcp120.dll and msvcr120.dll (Nmap.exe compiled with vs2013)\u003C\u002Fp>\u003Cp>Remove irrelevant files, streamline nmap, final required support file list as follows:\u003C\u002Fp>\u003Cul>\u003Cli>libeay32.dll\u003C\u002Fli>\u003Cli>msvcp120.dll\u003C\u002Fli>\u003Cli>msvcr120.dll\u003C\u002Fli>\u003Cli>nmap-mac-prefixes\u003C\u002Fli>\u003Cli>nmap-os-db\u003C\u002Fli>\u003Cli>nmap-payloads\u003C\u002Fli>\u003Cli>nmap-services\u003C\u002Fli>\u003Cli>nmap.exe\u003C\u002Fli>\u003Cli>ssleay32.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Scan specified network segment and ports:\u003C\u002Fp>\u003Cp>nmap.exe -p80 192.168.81.1-255\u003C\u002Fp>\u003Cp>or\u003C\u002Fp>\u003Cp>nmap.exe -p80 192.168.81.1\u002F24\u003C\u002Fp>\u003Cp>Scan IP address list:\u003C\u002Fp>\u003Cp>nmap.exe iL IP.txt\u003C\u002Fp>\u003Cp>Scan all open ports on specified host:\u003C\u002Fp>\u003Cp>nmap.exe 192.168.81.143\u003C\u002Fp>\u003Cp>Scan specific ports on specified host:\u003C\u002Fp>\u003Cp>nmap.exe -p80,443 192.168.81.143\u003C\u002Fp>\u003Cp>Operating system detection (-O):\u003C\u002Fp>\u003Cp>nmap.exe -O 192.168.81.143\u003C\u002Fp>\u003Cp>Service version detection on ports (-sV):\u003C\u002Fp>\u003Cp>nmap.exe -sV 192.168.81.143\u003C\u002Fp>\u003Cp>Port scanning as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870775_7_77dd4b05ea.jpeg\">\u003C\u002Fp>\u003Cp>Version detection as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019875241_8_4402bd9581.jpeg\">\u003C\u002Fp>\u003Cp>Comparison shows that version detection can identify service versions on ports\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To restore version detection (-sV), the following files need to be added:\u003C\u002Fp>\u003Cul>\u003Cli>nse_main.lua\u003C\u002Fli>\u003Cli>nmap-service-probes\u003C\u002Fli>\u003Cli>nselib folder and files within it\u003C\u002Fli>\u003Cli>scripts folder and files within it\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Route information detection (--traceroute)\u003C\u002Fp>\u003Cp>nmap.exe --traceroute 192.168.81.143\u003C\u002Fp>\u003Cp>Comprehensive Detection (-A)\u003C\u002Fp>\u003Cp>Includes operating system, service version, and routing information, essentially the combination of the above three\u003C\u002Fp>\u003Cp>nmap.exe -A 192.168.81.143\u003C\u002Fp>\u003Cp>Scan methods support the following parameters:\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>-sS\u002FsT\u002FsA\u002FsW\u002FsM: TCP SYN\u002FConnect()\u002FACK\u002FWindow\u002FMaimon scans\u003C\u002Fp>\u003Cp>-sU: UDP Scan\u003C\u002Fp>\u003Cp>-sN\u002FsF\u002FsX: TCP Null, FIN, and Xmas scans\u003C\u002Fp>\u003Cp>--scanflags \u003Cflags>: Customize TCP scan flags\u003C\u002Fflags>\u003C\u002Fp>\u003Cp>-sI \u003Czombie host[:probeport]=\"\">: Idle scan\u003C\u002Fzombie>\u003C\u002Fp>\u003Cp>-sY\u002FsZ: SCTP INIT\u002FCOOKIE-ECHO scans\u003C\u002Fp>\u003Cp>-sO: IP protocol scan\u003C\u002Fp>\u003Cp>-b \u003Cftp relay=\"\" host=\"\">: FTP bounce scan\u003C\u002Fftp>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Ch3>Introduction to common scanning methods:\u003C\u002Fh3>\u003Cp>TCP SYN Scan (-sS)\u003C\u002Fp>\u003Cul>\u003Cli>Half-open scanning, does not establish a full three-way handshake connection, very fast\u003C\u002Fli>\u003Cli>Default scanning method in nmap\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP connect scan (-sT)\u003C\u002Fp>\u003Cul>\u003Cli>Completes the three-way handshake process (SYN, SYN\u002FACK, ACK), but speed is reduced\u003C\u002Fli>\u003Cli>Easily detected\u003C\u002Fli>\u003C\u002Ful>\u003Cp>UDP scan (-sU)\u003C\u002Fp>\u003Cul>\u003Cli>Scans UDP ports\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP Null\u002FFIN\u002FXmas scan (-sN\u002F-sF\u002F-sX)\u003C\u002Fp>\u003Cul>\u003Cli>Used to determine if a port is open\u003C\u002Fli>\u003Cli>Can bypass some stateless firewalls\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Null scan (-sN)\u003C\u002Fp>\u003Cul>\u003Cli>Sets no flags (TCP flag header is 0)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>FIN scan (-sF)\u003C\u002Fp>\u003Cul>\u003Cli>Sets only the TCP FIN flag\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Xmas scan (-sX)\u003C\u002Fp>\u003Cul>\u003Cli>Set FIN, PSH, and URG flags\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP ACK scan (-sA)\u003C\u002Fp>\u003Cul>\u003Cli>Not used to determine if a port is open\u003C\u002Fli>\u003Cli>Used to discover firewall rules, determine whether firewall rules are stateful or stateless, and which ports are filtered\u003C\u002Fli>\u003Cli>Only set the ACK flag\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Custom TCP scan (--scanflags)\u003C\u002Fp>\u003Cul>\u003Cli>Manually specify arbitrary TCP flags to design custom scans\u003C\u002Fli>\u003Cli>Can be used to bypass intrusion detection systems\u003C\u002Fli>\u003Cli>Requires in-depth understanding of communication protocols\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Idle scan (-sI)\u003C\u002Fp>\u003Cul>\u003Cli>Spoof the source address of the scan\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The host at this source address must be online\u003C\u002Fp>\u003Cp>Can also spoof the source port, default is port 80\u003C\u002Fp>\u003Cp>Forged source port format is as follows:\u003C\u002Fp>\u003Cp> \u003Czombie host[:probeport]=\"\">\u003C\u002Fzombie>\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>nmap.exe -sI 192.168.81.1:1234 192.168.81.143\u003C\u002Fp>\u003Cp>PING Scan (-sP)\u003C\u002Fp>\u003Cul>\u003Cli>Use ping to scan if the host is online\u003C\u002Fli>\u003C\u002Ful>\u003Cp>No PING Scan (-PN)\u003C\u002Fp>\u003Cul>\u003Cli>Do not use ping for scanning\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PN two letters are uppercase\u003C\u002Fp>\u003Cp>Output format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>-oN \u003Cfilespec> (standard)\u003Cbr>-oX \u003Cfilespec> (XML)\u003Cbr>-oS \u003Cfilespec> (ScRipT KIdd|3 oUTpuT)\u003Cbr>nmap default output is all uppercase format, using -oS will randomly change letter case\u003Cbr>-oG \u003Cfilespec> (Grep)\u003Cbr>-oA \u003Cbasename> (Output to all formats)\u003Cbr>Set the file name to output three formats at once: standard (.nmap), XML (.xml), and Grep (.gnmap)\u003C\u002Fbasename>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnmap.org\u002Fbook\u002F for more Nmap usage introduction\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the command-line usage of Masscan and Nmap on the Windows platform, while reminding everyone from a defensive perspective that internal network security is equally important and should be handled with caution.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In internal network penetration, information gathering is particularly important.\u003C\u002Fp>\u003Cp>Facing the complex environment of internal networks, although network scanning can easily expose oneself, scanning can discover information such as surviving hosts, open ports, running services, and operating systems within the internal network, laying the foundation for further penetration.\u003C\u002Fp>\u003Cp>When selecting scanning tools, one must consider not only functionality but also the applicability of the tools.\u003C\u002Fp>\u003Cp>In reality, the pivot machine is often not a Linux server and lacks a suitable environment to install Nmap, Zmap, and Masscan.\u003C\u002Fp>\u003Cp>In other words, which command-line scanning tools can be used directly under Windows?\u003C\u002Fp>\u003Cp>The well-known open-source scanning tools Nmap, Zmap, and Masscan each have their own unique features in terms of functionality.\u003C\u002Fp>\u003Cp>In terms of applicability, Zmap requires the installation of Cygwin to run on Windows, so it is not within the scope of consideration.\u003C\u002Fp>\u003Cp>Masscan supports compilation for the Windows platform, and Nmap provides a command-line version, making Masscan and Nmap appear to meet the requirements.\u003C\u002Fp>\u003Cp>However, both Masscan and Nmap require WinPcap support, meaning WinPcap must be installed before use.\u003C\u002Fp>\u003Cp>So, can WinPcap be installed via the command line?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article aims to address the above issues and introduces the following content:\u003C\u002Fp>\u003Cul>\u003Cli>Compiling Masscan on Windows Platform\u003C\u002Fli>\u003Cli>Installing WinPcap via Windows Command Line\u003C\u002Fli>\u003Cli>Introduction to Using Masscan\u003C\u002Fli>\u003Cli>Introduction to Configuring and Using Nmap\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Compiling Masscan on Windows Platform\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Masscan Download Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Frobertdavidgraham\u002Fmasscan\u002F\u003C\u002Fp>\u003Cp>Compilation Tool: vs2012\u003C\u002Fp>\u003Cp>The compilation options do not include configuration for vs2012, so direct compilation will result in errors\u003C\u002Fp>\u003Cp>\u003Cstrong>Solution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Add vs2012 configuration information in string_s.h\u003C\u002Fp>\u003Cp>Located in misc-string_s.h, add the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#if defined(_MSC_VER) &amp;&amp; (_MSC_VER == 1700)\u003Cbr>\u002F*Visual Studio 2012*\u002F\u003Cbr># include \u003Cstdio.h>\u003Cbr># include \u003Cstring.h>\u003Cbr># define strcasecmp     _stricmp\u003Cbr># define memcasecmp     _memicmp\u003Cbr># ifndef PRIu64\u003Cbr>#  define PRIu64 \"llu\"\u003Cbr>#  define PRId64 \"lld\"\u003Cbr>#  define PRIx64 \"llx\"\u003Cbr># endif\u003C\u002Fstring.h>\u003C\u002Fstdio.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compilation successful, executing masscan.exe, prompts Packet.dll: not found\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019797369_0_6550627260-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Method to obtain Packet.dll:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing WinPcap, obtain it under System32\u003C\u002Fp>\u003Cp>\u003Cstrong>WinPcap download address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.winpcap.org\u002Finstall\u002Fdefault.htm\u003C\u002Fp>\u003Cp>Install WinPcap on another system, locate Packet.dll and Wpcap.dll under System32, copy them to the same directory as masscan.exe on the test system, and run again\u003C\u002Fp>\u003Cp>The program starts normally but cannot scan, reporting the following error:\u003C\u002Fp>\u003Cp>`FAIL: Error opening adapter: The system cannot find the device specified. (20)\u003C\u002Fp>\u003Cp>adapter[\\Device\\NPF_{71D19B82-0818-4685-A8E7-A6C7C812F2EA}].init: failed`\u003C\u002Fp>\u003Cp>\u003Cstrong>Question: Does the test system also need to install WinPcap to use it?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After actual testing, indeed it does\u003C\u002Fp>\u003Ch2>0x03 Installing WinPcap via Windows Command Line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Testing on a 32-bit system:\u003C\u002Fh3>\u003Cp>Using ProcessMonitor to monitor the WinPcap installation process (32-bit system), the following information was obtained:\u003C\u002Fp>\u003Cul>\u003Cli>Releases packet.dll and wpcap.dll in the \\system32\\ folder\u003C\u002Fli>\u003Cli>Releases npf.sys in \\system32\\drivers\\\u003C\u002Fli>\u003Cli>Installs the npf service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Obtain configuration information of the installed service npf through the sc command:\u003C\u002Fp>\u003Cp>sc qc npf\u003C\u002Fp>\u003Cp>Information obtained as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[SC] QueryServiceConfig SUCCESS\u003Cbr>\u003Cbr>SERVICE_NAME: npf\u003Cbr>        TYPE               : 1  KERNEL_DRIVER\u003Cbr>        START_TYPE         : 3   DEMAND_START\u003Cbr>        ERROR_CONTROL      : 1   NORMAL\u003Cbr>        BINARY_PATH_NAME   : system32\\drivers\\npf.sys\u003Cbr>        LOAD_ORDER_GROUP   :\u003Cbr>        TAG                : 0\u003Cbr>        DISPLAY_NAME       : NetGroup Packet Filter Driver\u003Cbr>        DEPENDENCIES       :\u003Cbr>        SERVICE_START_NAME :\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019807883_1_8c9aab43e0-1.jpeg\">\u003C\u002Fp>\u003Cp>View running status:\u003C\u002Fp>\u003Cp>sc query npf\u003C\u002Fp>\u003Cp>Information obtained is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SERVICE_NAME: npf\u003Cbr>        TYPE               : 1  KERNEL_DRIVER\u003Cbr>        STATE              : 4  RUNNING\u003Cbr>                                (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)\u003Cbr>        WIN32_EXIT_CODE    : 0  (0x0)\u003Cbr>        SERVICE_EXIT_CODE  : 0  (0x0)\u003Cbr>        CHECKPOINT         : 0x0\u003Cbr>        WAIT_HINT          : 0x0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019821455_2_43b9a79ccd-1.jpeg\">\u003C\u002Fp>\u003Cp>Corresponding registry keys and values will be created, indicating service configuration information, location as follows:\u003C\u002Fp>\u003Cul>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\npf\u003C\u002Fli>\u003Cli>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\npf\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019831687_3_e88ae2e0e4-1.jpeg\">\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019846254_4_2ba688a421-1.jpeg\">\u003C\u002Fp>\u003Cp>It is speculated that as long as the above installation operations can be simulated, WinPcap can be installed via the command line.\u003C\u002Fp>\u003Cp>\u003Cstrong>The simulated installation operations are as follows:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Release files\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>copy packet.dll %SystemRoot%\\system32\\\u003C\u002Fp>\u003Cp>copy wpcap.dll %SystemRoot%\\system32\\\u003C\u002Fp>\u003Cp>copy npf.sys %SystemRoot%\\system32\\drivers\\`\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Create service\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>sc create npf binPath= system32\\drivers\\npf.sys type= kernel start= demand error= normal tag= no DisplayName= \"NetGroup Packet Filter Driver\"\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Start the service\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>sc start npf\u003C\u002Fp>\u003Cp>Test commands are as follows:\u003C\u002Fp>\u003Cp>masscan.exe -p80 192.168.81.143\u003C\u002Fp>\u003Cp>Successfully executed masscan.exe, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019862534_5_8e94ea104a-1.jpeg\">\u003C\u002Fp>\u003Ch3>Test 64-bit system:\u003C\u002Fh3>\u003Cp>Using ProcessMonitor to monitor the WinPcap installation process (32-bit system), obtained the following information:\u003C\u002Fp>\u003Cul>\u003Cli>Release 64-bit packet.dll and wpcap.dll in the \\system32\\ folder\u003C\u002Fli>\u003Cli>Release 64-bit npf.sys in the \\system32\\drivers\\ folder\u003C\u002Fli>\u003Cli>Release 32-bit packet.dll, wpcap.dll, and pthreadVC.dll in the \\syswow64\\ folder\u003C\u002Fli>\u003Cli>Install the npf service\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Through actual testing and optimization, when executing 32-bit masscan.exe in a 64-bit environment, 64-bit packet.dll and wpcap.dll are not required, 32-bit pthreadVC.dll is not required, only the 64-bit driver npf.sys needs to be installed\u003C\u002Fp>\u003Cp>Moreover, whether on a 32-bit or 64-bit system, packet.dll and wpcap.dll can be placed in the same directory as masscan.exe (of course, since it is compiled with vs2012, msvcr110d.dll is also required)\u003C\u002Fp>\u003Cp>That is to say, for 32-bit and 64-bit systems, it is only necessary to copy different versions of npf.sys to the \\system32\\drivers\\ folder.\u003C\u002Fp>\u003Cp>Then create the service npf and install it, and the entire process is completed.\u003C\u002Fp>\u003Cp>Automate the above process through batch processing, the one-click installation script code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>@echo off\u003Cbr>cd %~dp0\u003Cbr>if \"%PROCESSOR_ARCHITECTURE%\"==\"x86\" move npf_x86.sys %SystemRoot%\\system32\\drivers\\npf.sys\u003Cbr>if \"%PROCESSOR_ARCHITECTURE%\"==\"AMD64\" move npf_x64.sys %SystemRoot%\\system32\\drivers\\npf.sys\u003Cbr>if exist %SystemRoot%\\system32\\drivers\\npf.sys (echo move success!) else (echo move error!)\u003Cbr>sc create npf binPath= system32\\drivers\\npf.sys type= kernel start= demand error= normal tag= no DisplayName= \"NetGroup Packet Filter Driver\"\u003Cbr>sc start npf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The relevant code and required dll files have been uploaded to GitHub, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Masscan Usage Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Scan specified network segment and ports:\u003C\u002Fp>\u003Cp>masscan.exe -p80 192.168.81.1\u002F24\u003C\u002Fp>\u003Cp>Found a server with port 80 open, response as follows:\u003C\u002Fp>\u003Cp>Discovered open port 80\u002Ftcp on 192.168.81.143\u003C\u002Fp>\u003Cp>Scan all open ports on the specified host:\u003C\u002Fp>\u003Cp>masscan.exe -p0-65535 192.168.81.143\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867320_6_a7a33d25f0-1.jpeg\">\u003C\u002Fp>\u003Cp>Scan specific ports on the specified host:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443 192.168.81.143\u003C\u002Fp>\u003Cp>Retrieve banners:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443,3306 192.168.81.143 --banners\u003C\u002Fp>\u003Cp>Start scan via configuration file:\u003C\u002Fp>\u003Cp>Save configuration information in 1.conf:\u003C\u002Fp>\u003Cp>masscan.exe -p80,443,3306 192.168.81.143 --banners --echo&gt;1.conf\u003C\u002Fp>\u003Cp>Read configuration file 1.conf and start scan:\u003C\u002Fp>\u003Cp>masscan.exe -c 1.conf\u003C\u002Fp>\u003Cp>Modify scanning speed to 100,000 packets\u002Fsecond (maximum 300,000 packets\u002Fsecond on Windows), default is 100 packets\u002Fsecond:\u003C\u002Fp>\u003Cp>--rate 100000\u003C\u002Fp>\u003Cp>Output formats:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>-oX \u003Cfilespec> (XML)\u003Cbr>-oB \u003Cfilespec> (Binary)\u003Cbr>-oG \u003Cfilespec> (Grep)\u003Cbr>-oJ \u003Cfilespec> (Json)\u003Cbr>-oL \u003Cfilespec> (List)\u003Cbr>-oU \u003Cfilespec> (Unicornscan format)\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additionally, by default, masscan enables the following configurations:\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>-sS: this does SYN scan only (currently, will change in the future)\u003C\u002Fp>\u003Cp>-Pn: doesn't ping hosts first, which is fundamental to the async operation\u003C\u002Fp>\u003Cp>-n: no DNS resolution happens\u003C\u002Fp>\u003Cp>--randomize-hosts: scan completely randomized\u003C\u002Fp>\u003Cp>--send-eth: sends using raw libpcap\u003C\u002Fp>\u003Ch2>0x05 Nmap Configuration and Usage Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Nmap Zip Version Download Address:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnmap.org\u002Fdist\u002Fnmap-7.50-win32.zip\u003C\u002Fp>\u003Cp>Using Nmap also requires installing WinPcap in advance via command line\u003C\u002Fp>\u003Cp>Also add vs2013 dlls: msvcp120.dll and msvcr120.dll (Nmap.exe compiled with vs2013)\u003C\u002Fp>\u003Cp>Remove irrelevant files, streamline nmap, final required support file list as follows:\u003C\u002Fp>\u003Cul>\u003Cli>libeay32.dll\u003C\u002Fli>\u003Cli>msvcp120.dll\u003C\u002Fli>\u003Cli>msvcr120.dll\u003C\u002Fli>\u003Cli>nmap-mac-prefixes\u003C\u002Fli>\u003Cli>nmap-os-db\u003C\u002Fli>\u003Cli>nmap-payloads\u003C\u002Fli>\u003Cli>nmap-services\u003C\u002Fli>\u003Cli>nmap.exe\u003C\u002Fli>\u003Cli>ssleay32.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Scan specified network segment and ports:\u003C\u002Fp>\u003Cp>nmap.exe -p80 192.168.81.1-255\u003C\u002Fp>\u003Cp>or\u003C\u002Fp>\u003Cp>nmap.exe -p80 192.168.81.1\u002F24\u003C\u002Fp>\u003Cp>Scan IP address list:\u003C\u002Fp>\u003Cp>nmap.exe iL IP.txt\u003C\u002Fp>\u003Cp>Scan all open ports on specified host:\u003C\u002Fp>\u003Cp>nmap.exe 192.168.81.143\u003C\u002Fp>\u003Cp>Scan specific ports on specified host:\u003C\u002Fp>\u003Cp>nmap.exe -p80,443 192.168.81.143\u003C\u002Fp>\u003Cp>Operating system detection (-O):\u003C\u002Fp>\u003Cp>nmap.exe -O 192.168.81.143\u003C\u002Fp>\u003Cp>Service version detection on ports (-sV):\u003C\u002Fp>\u003Cp>nmap.exe -sV 192.168.81.143\u003C\u002Fp>\u003Cp>Port scanning as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870775_7_77dd4b05ea-1.jpeg\">\u003C\u002Fp>\u003Cp>Version detection as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019875241_8_4402bd9581-1.jpeg\">\u003C\u002Fp>\u003Cp>Comparison shows that version detection can identify service versions on ports\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>To restore version detection (-sV), the following files need to be added:\u003C\u002Fp>\u003Cul>\u003Cli>nse_main.lua\u003C\u002Fli>\u003Cli>nmap-service-probes\u003C\u002Fli>\u003Cli>nselib folder and files within it\u003C\u002Fli>\u003Cli>scripts folder and files within it\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Route information detection (--traceroute)\u003C\u002Fp>\u003Cp>nmap.exe --traceroute 192.168.81.143\u003C\u002Fp>\u003Cp>Comprehensive Detection (-A)\u003C\u002Fp>\u003Cp>Includes operating system, service version, and routing information, essentially the combination of the above three\u003C\u002Fp>\u003Cp>nmap.exe -A 192.168.81.143\u003C\u002Fp>\u003Cp>Scan methods support the following parameters:\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Cp>-sS\u002FsT\u002FsA\u002FsW\u002FsM: TCP SYN\u002FConnect()\u002FACK\u002FWindow\u002FMaimon scans\u003C\u002Fp>\u003Cp>-sU: UDP Scan\u003C\u002Fp>\u003Cp>-sN\u002FsF\u002FsX: TCP Null, FIN, and Xmas scans\u003C\u002Fp>\u003Cp>--scanflags \u003Cflags>: Customize TCP scan flags\u003C\u002Fflags>\u003C\u002Fp>\u003Cp>-sI \u003Czombie host[:probeport]=\"\">: Idle scan\u003C\u002Fzombie>\u003C\u002Fp>\u003Cp>-sY\u002FsZ: SCTP INIT\u002FCOOKIE-ECHO scans\u003C\u002Fp>\u003Cp>-sO: IP protocol scan\u003C\u002Fp>\u003Cp>-b \u003Cftp relay=\"\" host=\"\">: FTP bounce scan\u003C\u002Fftp>\u003C\u002Fp>\u003Cp>`\u003C\u002Fp>\u003Ch3>Introduction to common scanning methods:\u003C\u002Fh3>\u003Cp>TCP SYN Scan (-sS)\u003C\u002Fp>\u003Cul>\u003Cli>Half-open scanning, does not establish a full three-way handshake connection, very fast\u003C\u002Fli>\u003Cli>Default scanning method in nmap\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP connect scan (-sT)\u003C\u002Fp>\u003Cul>\u003Cli>Completes the three-way handshake process (SYN, SYN\u002FACK, ACK), but speed is reduced\u003C\u002Fli>\u003Cli>Easily detected\u003C\u002Fli>\u003C\u002Ful>\u003Cp>UDP scan (-sU)\u003C\u002Fp>\u003Cul>\u003Cli>Scans UDP ports\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP Null\u002FFIN\u002FXmas scan (-sN\u002F-sF\u002F-sX)\u003C\u002Fp>\u003Cul>\u003Cli>Used to determine if a port is open\u003C\u002Fli>\u003Cli>Can bypass some stateless firewalls\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Null scan (-sN)\u003C\u002Fp>\u003Cul>\u003Cli>Sets no flags (TCP flag header is 0)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>FIN scan (-sF)\u003C\u002Fp>\u003Cul>\u003Cli>Sets only the TCP FIN flag\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Xmas scan (-sX)\u003C\u002Fp>\u003Cul>\u003Cli>Set FIN, PSH, and URG flags\u003C\u002Fli>\u003C\u002Ful>\u003Cp>TCP ACK scan (-sA)\u003C\u002Fp>\u003Cul>\u003Cli>Not used to determine if a port is open\u003C\u002Fli>\u003Cli>Used to discover firewall rules, determine whether firewall rules are stateful or stateless, and which ports are filtered\u003C\u002Fli>\u003Cli>Only set the ACK flag\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Custom TCP scan (--scanflags)\u003C\u002Fp>\u003Cul>\u003Cli>Manually specify arbitrary TCP flags to design custom scans\u003C\u002Fli>\u003Cli>Can be used to bypass intrusion detection systems\u003C\u002Fli>\u003Cli>Requires in-depth understanding of communication protocols\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Idle scan (-sI)\u003C\u002Fp>\u003Cul>\u003Cli>Spoof the source address of the scan\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The host at this source address must be online\u003C\u002Fp>\u003Cp>Can also spoof the source port, default is port 80\u003C\u002Fp>\u003Cp>Forged source port format is as follows:\u003C\u002Fp>\u003Cp> \u003Czombie host[:probeport]=\"\">\u003C\u002Fzombie>\u003C\u002Fp>\u003Cp>Example:\u003C\u002Fp>\u003Cp>nmap.exe -sI 192.168.81.1:1234 192.168.81.143\u003C\u002Fp>\u003Cp>PING Scan (-sP)\u003C\u002Fp>\u003Cul>\u003Cli>Use ping to scan if the host is online\u003C\u002Fli>\u003C\u002Ful>\u003Cp>No PING Scan (-PN)\u003C\u002Fp>\u003Cul>\u003Cli>Do not use ping for scanning\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PN two letters are uppercase\u003C\u002Fp>\u003Cp>Output format:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>-oN \u003Cfilespec> (standard)\u003Cbr>-oX \u003Cfilespec> (XML)\u003Cbr>-oS \u003Cfilespec> (ScRipT KIdd|3 oUTpuT)\u003Cbr>nmap default output is all uppercase format, using -oS will randomly change letter case\u003Cbr>-oG \u003Cfilespec> (Grep)\u003Cbr>-oA \u003Cbasename> (Output to all formats)\u003Cbr>Set the file name to output three formats at once: standard (.nmap), XML (.xml), and Grep (.gnmap)\u003C\u002Fbasename>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Ffilespec>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fnmap.org\u002Fbook\u002F for more Nmap usage introduction\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the command-line usage of Masscan and Nmap on the Windows platform, while reminding everyone from a defensive perspective that internal network security is equally important and should be handled with caution.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1553,"Onedaysec",8,"published","2026-02-02T08:19:47.662Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Running Masscan and Nmap on Windows for Penetration Testing","masscan windows, nmap windows, penetration testing, internal network scanning, winpcap installation, command line tools, network security, information gathering",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],183,182,181,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.861Z","2026-07-23T16:01:08.848Z","draft","2026-07-23T16:04:21.039Z"]