Flag
Description
-sn
Host discovery scan (ping sweep)
-sL
List scan, show IPs and hostnames only
-PS <port></port>
TCP SYN ping on specific ports
-PA <port></port>
TCP ACK ping
-PU <port></port>
UDP ping
-sY
SCTP INIT ping
-Pn
Treat all hosts as up (skip discovery)
-sS
TCP SYN (half-open) scan
-sT
TCP connect (full handshake) scan
-sN
Null scan (no flags set)
-sF
FIN scan
-sX
Xmas scan (FIN+PSH+URG flags)
-sU
UDP scan
-sI
Idle (zombie) scan
-p
Specify port(s) or port range
-f / –mtu
Fragment packets to bypass IDS/IPS
–scan-delay <time></time>
Delay between probes for stealth
-T<0–5>
Timing template (0=paranoid, 5=insane/fast)
-sV
Detect service versions
-A
Aggressive scan (OS, version, script, traceroute)
-O
OS detection
-oN
Normal output file
-oX
XML output