-T1
slow scan, avoid IDS/IPS
-sV
open ports, version information of services
-Pn
no ping, port scan only, no host discovery
-T 1-5
timing options
-T5
fastest scan, aggressive & noisy
-p
scan specified ports
-script=vuln
scan for CVE
-O
remote OS detection
-p-
scan all ports on a target
-sT
TCP connect scan
-sS
TCP SYN scan, stealth
-sU
UDP scan
-A
OS detection, version detection, script scanning, traceroute