Nmap - Scan Timing And Performance

HackerSploit · Intermediate ·🔐 Cybersecurity ·5y ago

Key Takeaways

The video demonstrates how to optimize Nmap scans using timing templates, parallelism, host group sizes, host timeout, scan delay, and packet rate.

Full Transcript

[Music] hey guys hackersploit here back again with another video welcome back to the penetration testing boot camp uh in this video we're going to be talking about scan timing and performance with nmap now in the previous video we we touched upon firewall evasion and we took a look at all the various techniques that you can use with nmap to evade firewalls and in that video i touched upon a very important element and that is the fact that you can use the various scan timing and performance techniques with nmap to also avoid firewalls and intrusion detection systems so the purpose of this video is to is to highlight that and we'll also be taking a look at the use of scan uh of scan timing and performance options to increase uh or to to speed up or slow down scans all right so nmap by default allows you to speed up and slow down scans based on the type of environment you're working in or the type of environment that you're targeting you know again you could be targeting an entire network or a particular host that is set up in a specific way it could they could be having you know some rate limiting in place or you could be performing scans on a network that has very old hardware and is susceptible to crashing right so this is very important as you may be dealing with network or business critical infrastructure that again as i said will not be able to handle uh heavy or noisy scans on the other hand you might you you you maybe want to sca to speed up your scans uh you know when you're performing large types of scans uh on on entire subnets or class class b and c networks and of course as i said you can then slow down scans to evade firewalls and intrusion detection system so we're going to be taking a look at a lot of techniques in this video and i'll just highlight them right now so that again we have a bit of order and in the description section there should be time stamps to each of these of these topics that we'll be covering so the first topic we'll be looking at is going to be of course timing templates number two we'll be taking a look at parallelism number three we'll take a look at the various host group sizes we can customize uh number four we'll take a look at host timeouts number five we'll take a look at scan delays and six we'll end off uh by taking a look at the packet rate and how to customize the minimum and maximum packet rate you can send or you can you you'll be using when performing a scan so let's get started with timing templates right so timing templates are used to run scans faster or slower based on your target or the working environment that you're in now the timing templates range from t0 to t5 0 being the slowest and 5 being the fastest so this is something that again you'll grasp really quickly so if i'm running a scan and i want to run an extremely slow scan i would start off with d0 right if i wanted to run the fastest scan i can run it with t5 now the great thing about these timing templates is they have names so t0 or we can just specify it by typing in t0 here that has a name of or the name of this timing template is paranoid so i'll be posting uh the write up of this particular video you can find it in the description section or or on hackersploit.org it will actually have a table where it it explains in detail what changes with these timing templates and the values that change in how they change right so when you're talking about a t0 this is the slowest type of scan and it really isn't used that much unless you're dealing with a very very specific type of environment when we talk about t1 the name for the t1 timing template is sneaky now sneaky is primarily used to evade intrusion detection systems it's a very very useful type of timing template and again you know the values that get changed are things like the scan delay is reduced to about 15 seconds and then of course the parallelism is is still set to serial you know we're really not using any any type of parallel operations here uh so that's t1 when you talk about t2 t2 has the name of polite so again t2 again is not really used primarily because it's uh it's in between t1 and t3 now when we talk about t3 t3 is known as the normal timing template and the reason it's known as the normal timing template is because this is the default timing template that nmap runs so for example if i run a default nmap scan on nmap.scanme.org and again this is a default this is a default nmap scan the default timing template that will be used is going to be t3 which again stands for normal you then have t4 which is an aggressive scan again t4 and this is the one that is most commonly used when you want to speed up your scan or you want to get your results much quicker you then have t5 which again is used on on networks and hosts that can actually handle this type of scan because it's extremely aggressive like when i say it's aggressive i mean this is an extremely aggressive scan so you want to use it cautiously all right so again just to highlight over that t0 stands for paranoid t1 is the sneaky scan t2 is the polite scan t3 is normal t4 is aggressive and t5 is known as the insane scan all right so we can actually i can actually demonstrate this right now now of course when talking about the slower types of scans they're going to take a while so what i'm going to do if i run a simple scan like nmap um we'll use a stealth scan and we'll specify a port range of maybe port 21 to port 80 well you know so something extremely simple and customized to specify the timing template we'll start off with the slowest template or t we'll use t1 and then i'll use t4 or t5 to actually contrast and show you the difference here so we'll use nmap.scanme.org and i'm just going to hit enter now and we'll hit enter and again this is an extremely slow scan and is as i said primarily used when you're dealing with rate limiting or an intrusion detection system so i'll just wait for this scan to complete i don't think i'll actually even be able to wait because you know of how slow it is and that's primarily why i specified my that is primarily why i specified a very customized uh very short type of scan uh what we can do is we can actually just customize this and i'll just say don't ping right so we'll skip you know host discovery and let's see whether this speeds up the scan again i'm just going to be using this for demonstration purposes and then we'll talk about the faster timing templates like t4 and t5 and as i said we'll be posting a table in the description section or on our website at hackersploit.org that'll actually explain uh what what is happening exactly and what changes with each of these timing templates what values are changed and most of these values will will actually be covering uh especially when talking about stuff like course delays etc so again you can see that this is taking quite a while uh the more information i try and get on the screen you can see it tells me that it's still about 0.83 done which again makes sense and uh right um so again i'll just hit enter and this is going to take a while it tells me it's going to take about 45 minutes so you get the idea this this scan will take a while and is extremely stealthy now if we increase this to something like t4 you'll actually see the difference in front of in front of yourself right now so again you see it's about 13.33 done 23 94 99 and it's done it completed that in about 7.55 seconds and that is much faster than 45 minutes but again these timing templates are you know are designed to be uh to be used under different scenarios now if we use the insane timing template uh you'll actually see there isn't going to be much of a difference between t4 and t5 so if i just demonstrate this to you you can see if we're on t5 it's going to run it in 3.67 whereas t4 run is 7.55 so really not much of a big difference if we run the default scan which again is going to be d3 i can just hit enter again the difference will really not be that uh we the the differences will be trivial however when you're running a larger type of scan that's where you're actually going to find a majority of the difference and these scans are used for again for when you want to get your results extremely quickly and you know the type of environment you're dealing with so you can see for the for the normal timing templates about 12.16 seconds for the 444 we have 7.55 and for t5 about 3.67 so again this pretty much explains the differences and again as i said the lower the the timing template the slower the scan and the more useful it is for evading intrusion detection systems and any rate limiting systems that might be in place great now that we've taken a look at timing templates let's take a look at parallelism now parallelism is a really simple concept to understand you're essentially an nmap when you run an nmf scan uh you depending on the type of scan you're running and the network environment you're running it on nmap will by default set up a minimum or maximum amount of parallel operations that are currently running your scan and this helps you increase or to speed up your scan and again reduce or slow down your scan so uh when we talk about parallelism and timing templates and the interrelationship uh again with a slower timing template the minimum or the maximum parallel uh of the maximum parallelism would be set to a low value value and then with the higher one the minimum would be set to a higher value so i'll explain that right now so as i said parallelism is used to specify the amount of parallel scanning processes that are being run during a scan so again yeah we we can do this so if i run a simple scan like nmap and we'll use uh we'll run a syn scan here again we'll just run the previous example uh port 21 to port 443 and we want to specify the minimum amount of parallel uh sessions we want running so minimum uh then we say para parallelism and we then specify the value so the minimum amount of parallel uh parallel operations we want running uh during this scan so again the higher the amount of the minimum parallels operations you want running the faster the scan so if we set this to 30 and i hit enter sorry uh parallel ism i just hit enter looks all right we need to specify our target apologies for that so nmap.scanme.org and i hit enter we'll just wait for this to complete so we've set the minimum amount of parallel operations to 30 so that'll again speed up the scan that again took about 7.03 seconds if we now change this to something like 50 again that'll set now the parallel operations to 50 you can see that this will perform the scan much faster and there you are about 2.64 seconds now you can see some very interesting results here and this is why i actually wanted to cover this or to actually highlight this area specifically when you increase the speed of your scan or the aggressiveness of your scan the results you will you will get will will will be most likely unre reliable so you want to be really careful with the with the options you specify in terms of the timing templates and the parallelism right so if i use a you know a reasonable amount of parallel operations like 10 i'll be guaranteed to get accurate results it'll take a few seconds more of course but i'll get you know the results that i'm looking for so in this case you can see it took about 7.88 seconds but i get accurate results and i'm i'm i'm very confident in the results that i get now when we talk about parallelism you can also specify maximum parallelism which again this is this is very useful because uh when you talk about maximum parallelism this this is now where you can really really uh you can structure your scan or fine-tune your scan in environments that have intrusion detection systems or if your target has rate limiting this is very very helpful so again we just change this for maximum so we say max parallelism and we can set this to something maybe like one and this is again very useful for uh for evasion and stuff like that so again if i it uh if i use one and it enter it's gonna take a while again you know this this might be similar to your your timing template but again if we hit enter you can see it's taking its own time but with this we're guaranteed to evade any systems in place any intrusion detection systems in place and secondly we are guaranteed that we'll get reliable scan results so again i'm really not going to go or to to you know to go through this scan because it's going to take a while however if i change this something again something reasonable like five uh and i hit enter and you know again you can see it gives you a summary of how much time this is going to take and again based on the type of scan you're performing you can fine tune this to exactly what you want and what you feel is comfortable and what you feel is appropriate so again i'm not going to go through this entire scan mainly because they're going to take a lot of time i just wanted to explain that so you want to be really really careful with the with the parameters you specify when talking about your minimum parallelism now by default nmap will automatically determine the amount of parallel operations to run based on the type of scan you're running and the network operations so if you're really not sure about what to run i don't recommend specifying parallelism unless you're sure of what you're doing the environment you're dealing with and the host or the target you're dealing with so that is parallelism in a nutshell now let's talk about host group sizes now when we talk about host group sizes that may sound like a really vague idea but what we're dealing with here and the scenario we need to to actually set up before we we start we get started with uh you know specifying the host group sizes is uh let's say we're performing a scan um you know a host discovery scan on a large network or on an entire subnet or on a class b network right uh these scans based on the type of scan we're performing will take a lot of time right and i just want to set up this premise because the next few techniques will be tailored towards these type of scans so you can customize the minimum and maximum host group size when performing large scans that involve entire subnets or class b networks so the host group size allows you to specify how many hosts you want to scan simultaneously so let's take a simple example let's say i'm saying nmap you know ss for a syn scan and we use the fast option here to scan only 100 ports i can then specify if if let's say we were scanning my entire subnet of 192.168.1.1 forward slash 24 and you know this is a large network right and the the type of scan we're running is stealthy and it's going to be relatively fast but i can specify uh the minimum host group so that is specified by typing in host group i can set this and i can specify the amount of hosts the minimum amount of hosts i want nmap to scan simultaneously so if i say i want nmap to scan 30 hosts simultaneously and that's the minimum value and then i hit enter this will be significantly faster than if i were to if i were to scan only five now again as i said you need to be careful with aggressive scans because you may get you you may get incredibly uh irregular or inaccurate results and that's because you're changing a lot of default values that again that again you might be giving you inaccurate results so again in this case you can see it's going through the entire subnet here and it's going through all the devices and uh in this case it's telling us you know it's giving us the results we're looking for it tells us you know the this ip is filtered et cetera et cetera and it's still going through the scan and uh it's about to it's about to hit uh the limit here it's about 255 ips so we're just going to let this run and and then again i'll compare it to something like uh or i'll use the maximum host group option which again will allow you to slow down or fine-tune your scan so you can see in this case it tells us and this is uh this is the problem here that nmap is done and we have about 256 ip addresses scanned uh 256 of them are up which again you can see it tells me for all of the ips they're all filtered but again for some here if i scroll the way down one second let me just go to the top here you can see that it gives me a few a few accurate pieces of information but if i set this to if i set the minimum host group to something like 10 or something reasonable then again i can get more accuracy accurate results now when you talk about uh you know the maximum host group option this again is used when you're really dealing with uh with various constraints on a network or you want to fine-tune your your scan to be as accurate as possible so i can say the maximum host group size i can set it to about five right and i'll hit enter and this hopefully will give me much more accurate results so again you can see it's now taking its time regards to in regards to the host discovery so there we are it's still running and it's still going to give us a fair bit of uh of information here in any case i'm not going to go through with the scan because again i'm just using this for demonstration so again you can specify the minimum and the maximum host screw host group size and again this is used when scanning a large uh large networks or when you're dealing with subnets now let's talk about an interesting technique that i personally really love demonstrating and that is the host timeout right so when you're talking about your host timeout this is used to specify the amount of time to elapse when scanning a target before skipping the host so let's say you're scanning a large network or you're dealing with a subnet or a class b network right and one of the issues that you'll typically run into is that a host will not respond right so nmap will send a packet but this device for some reason will take time to respond to that packet and in the event it doesn't respond or the device is offline uh nmap has essentially wasted that time waiting for that device to respond now this of course can cause issues if you're dealing with a network that is extremely slow you're dealing with rate limiting stuff like that so this is where the host timeout option comes into play this allows you to again specify a timeout period under which if a target does not respond nmap skips it and as i said this is very useful when scanning large networks so uh what we can do is we can run a a very default scan here so i'll say you know nmap and we'll then say you know we want to skip host discovery let's say i'm performing an extremely comprehensive scan on my network and i can run and i want to perform the scan i want all ports to be scanned all 65 535 ports and i want to run this on my entire network both class b and c so i say 192 168.1 uh 255 255. so you know both class b and class c this is a huge scan now the the as i said the the the problem or the issues that you you'll commonly be dealing with is some hosts will take a while to respond or maybe appear to be stuck based on various factors i said like the connection the the connection might be flaky the problem is nmap will wait for the for the target to respond and then of course if you analyze the packets uh again nmap will wait for response if there isn't a response it'll wait wait wait and that again that will slow down the scan so if you want to increase the speed of your scan you can set the host timeout to whatever value you feel is appropriate so host timeout and i can set this to something like maybe 30 seconds so what this means is if a target or a device on the network does not respond within 30 seconds skip it now this again can cause really really inaccurate or can give you really really inaccurate results because you you need to be careful in regards to the amount of time you provide uh for your host time on because a device may take even two minutes to respond and just because you skipped it doesn't does not mean it's offline so you want to be very careful with this so i hit enter and again that tells the the scan will wait for 30 seconds if a host does not respond within 30 seconds it moves on to the next one regardless of whether or not it's offline so again this scan is extremely huge i mean i'm you know performing a scan on on a lot of addresses here on both class b and c uh and again this these are the types of scans that you'll be performing you know when you're dealing with large subnets and you really need to know what you're doing regarding uh you know the type of responses you'll be dealing with so uh what i can do to just demonstrate that i can also make the scan run even faster is let's say i say i specify the the the host timeout to five seconds which this is an incredibly inaccurate type of scan to run but i'm just i'm just i'm trying to prove a point here so again that means if a host does not respond within five seconds you can see incredibly you can see how fast this is so uh immediately i'm being told uh 192.168.1.1 is up 1.2 is up 1.3 is up um sorry 1.2 was skipped sorry my bad uh only one i believe uh yeah you can see we're actually getting quite a few inaccurate results but uh 192.168.1.4 is up etc etc but you you can see we're getting inaccurate results and that's because we're really not giving nmap enough time or we're not giving the hosts enough time to respond and then based on that nmf says hey if you don't respond within five seconds i'm going to move on to the next host so that is how to specify your host timeout again you you need to be very careful with these options because they can greatly impact the accuracy of your scans now let's talk about scan delays scan delays is very simple to your host timeout right so your scan delay allows you to pause nmap for a specific amount of time uh between each probe or request that you send this is great when you're dealing with uh you know rate limiting firewalls or intrusion detection systems so i'll demonstrate this it's very very simple so let's say run a you know tcp connect scan or we will actually uh i want to specify the amount of time nmap will have to wait between each probe so before or before sending each prop so i say nmap this is a simple tcp connect scan and then i specify the scan delay i say the scan delay i want to set that to maybe 10 seconds right or i can say just say five seconds and um i then type in our target so nmap.scanme.org and you know i can use a tool like wireshark to show you this and you know it really is very very cool so uh i'll open up i'll start the capture and i'll hit enter and what you'll see is um nmap will wait for five seconds and then we'll send because this is a this is a tcp connect scan uh you're going to see that we have the synth scan being sent here and then uh after five seconds we get the other sin being sent and then after another five seconds you get the other sin being sent right uh and we're still waiting for the syna back from the target and then after another five seconds you get the sin after another five seconds you get the sin etc etc you get the point you can actually specify your sk you can actually specify a scan delay time or scan delay period so if i specify something like 10 seconds i'll actually show you that right now you'll be able to actually visualize this yourself so i'll start the captcha and i'll start the scan wait for 10 seconds there we are we have the first sin so one two three 4 5 6 7 8 9 10 and there we are we have the second sin being sent so again you can time this yourself and nmap is extremely accurate with that but again depending on your network conditions uh you know you want to give it one or two seconds you know plus or minus so that is how to specify your scan delay and you can see this is very useful because uh you don't if you if you're dealing with an environment or a target that is actively monitoring traffic right and you want to be as clandestine as possible you can reduce it to something like 30 seconds now of course the scan will take a lot of time but you'll not be a late uh you'll not be alerting any intrusion detection systems so that is scan delays and we move on to our final technique which is the packet rate so the packet rate is again is a technique that is used quite a bit and uh again this option allows you to specify the minimum and maximum amount of packets you want to send per second so that sounds exciting right so if we say nmap we run a simple tcp connect scan and we can then specify the minimum rate of packets we want to send per second so let's say i want to send 20 20 packets per second we say nmap dot scan me uh sorry nmap.scan scanme.org and we enter that's gonna send about 20 packets per second and we can start a new captcha and let's see whether this is indeed accurate so i'll hit enter and there you are you can see this is extremely aggressive type of scan and this is the type of stuff that alerts intrusion detection systems so there you go about 20 you know packets per second i can't even track uh how much it's sent already but again it's an extremely fast scan and yeah you can actually use this to speed up your scan you want to be very careful with that as i said and the scan is complete you can see because of the aggressiveness of the scan i wasn't able to get any results so if i change this to something like and i use the maximum rate now i say the maximum rate is maybe like something like two seconds or two packets per second which is much more reasonable right and i i'm just going to start a new capture here and we'll we'll just hit enter now and there we are you can see we're sending about two packets per second there we are there we are and and in this case we might be able to get you know or we will get more accurate results now the scan will take longer but again we'll get really really accurate results so again i'll just wait for this scan to complete and uh yeah that's pretty much these are pretty much all the techniques that i wanted to cover i know i haven't covered all the techniques available when it comes down to you know scan timing and performance uh and again i've pretty much covered the most important ones this scan is still running and yeah so we'll just wait for it to complete uh so again when talking about faster or aggressive types of scans i just want to summarize you want to be really careful because it will affect the accuracy of the results you get uh in terms of of dealing with you know networks or devices that really cannot handle that much traffic you want to use the slower or you want to slow down your scans again i recommend using timing templates you make use of parallelism very important and also you know you can you can specify your packet rate based on the type of scan you're running so um uh we'll just wait for this to this scan to complete it's again it's going to take a while because we're only limiting it to about two packets per second so i'm just going to end this scan here that's going to be it for this video thank you very much for watching if you found value in this video please leave a like down below it really helps the youtube algorithm you know put our videos in front of the right people if you have any question please post it in the comment section or you can hit us up on our social networks on twitter at hackersploit um a write-up of this particular video is going to be available on our website at hackersploit.org and you can join in the discussion on our forum at hackersploit.org or at forum.hackersploit.org and i'm going to be seeing you in the next video [Music] you

Original Description

In this video, I demonstrate how to optimize, speed up, and slow down your Nmap scans based on the type of network environment or target you are dealing with. Nmap is a free and open-source network scanner created by Gordon Lyon. Nmap is used to discover hosts and services on a computer network by sending packets and analyzing the responses. Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection. 0:00 Intro 2:31Timing Templates 9:05 Parallelism 14:08 Host Group Sizes 18:25 Host Timeout 23:10 Scan Delay 26:13 Packet Rate Writeup: https://hackersploit.org/nmap-scan-timing-performance Our videos are also available on the decentralized platform LBRY: https://lbry.tv/$/invite/@HackerSploit:26 � SUPPORT US: Patreon: https://www.patreon.com/hackersploit Merchandise: https://teespring.com/en-GB/stores/hackersploitofficial SOCIAL NETWORKS: Reddit: https://www.reddit.com/r/HackerSploit/ Twitter: https://twitter.com/HackerSploit Instagram: https://www.instagram.com/hackersploit/ LinkedIn: https://www.linkedin.com/company/18713892 WHERE YOU CAN FIND US ONLINE: HackerSploit - Open Source Cybersecurity Training: https://hackersploit.org/ HackerSploit Forum: https://forum.hackersploit.org HackerSploit Academy: https://www.hackersploit.academy LISTEN TO THE CYBERTALK PODCAST: Spotify: https://open.spotify.com/show/6j0RhRiofxkt39AskIpwP7 We hope you enjoyed the video and found value in the content. We value your feedback. If you have any questions or suggestions feel free to post them in the comments section or contact us directly via our social platforms. Thanks for watching! Благодарю за просмотр! Kiitos katsomisesta Danke fürs Zuschauen! 感谢您观看 Merci d'avoir regardé Obrigado por assistir دیکھنے کے لیے شکریہ देखने के लिए धन्यवाद Grazie per la visione Gracias por ver شكرا للمشاهدة #Nmap
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from HackerSploit · HackerSploit · 0 of 60

← Previous Next →
1 How To Install Kali Linux 2.0 On Virtual Box
How To Install Kali Linux 2.0 On Virtual Box
HackerSploit
2 100 Subscriber Q&A! - How I Learned Ethical Hacking
100 Subscriber Q&A! - How I Learned Ethical Hacking
HackerSploit
3 BlackArch Linux Review - Better Than Kali Linux?
BlackArch Linux Review - Better Than Kali Linux?
HackerSploit
4 How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
How to Access the Deep Web Safely | Deep Web Starter Guide 1.0
HackerSploit
5 Wireshark Tutorial for Beginners - Installation
Wireshark Tutorial for Beginners - Installation
HackerSploit
6 Wireshark Tutorial for Beginners - Overview of the environment
Wireshark Tutorial for Beginners - Overview of the environment
HackerSploit
7 Wireshark Tutorial for Beginners - Capture options
Wireshark Tutorial for Beginners - Capture options
HackerSploit
8 Wireshark Tutorial for Beginners - Filters
Wireshark Tutorial for Beginners - Filters
HackerSploit
9 Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
Complete Ethical Hacking Course - Become a Hacker Today - #1 Hacking Terminology
HackerSploit
10 Complete Ethical Hacking Course #2 - Installing Kali Linux
Complete Ethical Hacking Course #2 - Installing Kali Linux
HackerSploit
11 Parrot OS 3.5 Review | The Best Kali Linux Alternative
Parrot OS 3.5 Review | The Best Kali Linux Alternative
HackerSploit
12 Nmap Tutorial For Beginners - 1 - What is Nmap?
Nmap Tutorial For Beginners - 1 - What is Nmap?
HackerSploit
13 Katoolin | How To Install Pentesting Tools On Any Linux Distro
Katoolin | How To Install Pentesting Tools On Any Linux Distro
HackerSploit
14 Nmap Tutorial For Beginners - 2 - Advanced Scanning
Nmap Tutorial For Beginners - 2 - Advanced Scanning
HackerSploit
15 Nmap Tutorial For Beginners - 3 - Aggressive Scanning
Nmap Tutorial For Beginners - 3 - Aggressive Scanning
HackerSploit
16 Zenmap Tutorial For Beginners
Zenmap Tutorial For Beginners
HackerSploit
17 How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
How To Setup Proxychains In Kali Linux - #1 - Stay Anonymous
HackerSploit
18 How To Setup Proxychains In Kali Linux - #2 - Change Your IP
How To Setup Proxychains In Kali Linux - #2 - Change Your IP
HackerSploit
19 How To Change Mac Address In Kali Linux | Macchanger
How To Change Mac Address In Kali Linux | Macchanger
HackerSploit
20 How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
How To Setup And Use anonsurf On Kali Linux | Stay Anonymous
HackerSploit
21 Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
Ubuntu 17.04 "Zesty Zapus" Review - Bye Unity
HackerSploit
22 VPN And DNS For Beginners | Kali Linux
VPN And DNS For Beginners | Kali Linux
HackerSploit
23 Tails OS Installation And Review - Access The Deep Web/Dark Net
Tails OS Installation And Review - Access The Deep Web/Dark Net
HackerSploit
24 Steganography Tutorial - Hide Messages In Images
Steganography Tutorial - Hide Messages In Images
HackerSploit
25 The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
The Lazy Script - Kali Linux 2017.1 - Automate Penetration Testing!
HackerSploit
26 Best Linux Distributions For Penetration Testing
Best Linux Distributions For Penetration Testing
HackerSploit
27 Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
Netcat Tutorial - The Swiss Army Knife Of Networking - Reverse Shell
HackerSploit
28 Gaining Access - Web Server Hacking - Metasploitable - #1
Gaining Access - Web Server Hacking - Metasploitable - #1
HackerSploit
29 Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
Web Server Hacking - FTP Backdoor Command Execution With Metasploit - #2
HackerSploit
30 How To Install Kali Linux On VMware  - Complete Guide 2018
How To Install Kali Linux On VMware - Complete Guide 2018
HackerSploit
31 Q&A #1 - Best Cyber-security Certifications?
Q&A #1 - Best Cyber-security Certifications?
HackerSploit
32 Terminator - Kali Linux - Multiple Terminals
Terminator - Kali Linux - Multiple Terminals
HackerSploit
33 Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
Shodan Search Engine Tutorial - Access Routers,Servers,Webcams + Install CLI
HackerSploit
34 Q&A #2 - Mr Robot?
Q&A #2 - Mr Robot?
HackerSploit
35 Metasploit Community Web GUI  - Installation And Overview
Metasploit Community Web GUI - Installation And Overview
HackerSploit
36 Linux Expl0rer - Forensics Toolbox - Installation & Configuration
Linux Expl0rer - Forensics Toolbox - Installation & Configuration
HackerSploit
37 QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
QuasarRAT - The Best Windows RAT? - Remote Administration Tool for Windows
HackerSploit
38 Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
Metasploit For Beginners - #1 - The Basics - Modules, Exploits & Payloads
HackerSploit
39 Metasploit For Beginners - #2 - Understanding Metasploit Modules
Metasploit For Beginners - #2 - Understanding Metasploit Modules
HackerSploit
40 Kali Linux Quick Tips - #1 - Adding a non-root user
Kali Linux Quick Tips - #1 - Adding a non-root user
HackerSploit
41 Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
Metasploit For Beginners - #3 - Information Gathering - Auxiliary Scanners
HackerSploit
42 Spectre Meltdown Vulnerability  - How To Check Your System
Spectre Meltdown Vulnerability - How To Check Your System
HackerSploit
43 Metasploit For Beginners - #4 - Basic Exploitation
Metasploit For Beginners - #4 - Basic Exploitation
HackerSploit
44 ARP Spoofing With arpspoof - MITM
ARP Spoofing With arpspoof - MITM
HackerSploit
45 WordPress Vulnerability Scanning With WPScan
WordPress Vulnerability Scanning With WPScan
HackerSploit
46 Generating A PHP Backdoor with weevely
Generating A PHP Backdoor with weevely
HackerSploit
47 Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
Nikto Web Vulnerability Scanner - Web Penetration Testing - #1
HackerSploit
48 How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
How To Install Kali Linux On Windows 10 - Windows Subsystem For Linux
HackerSploit
49 Stacer - System Optimizer And Monitoring Tool For Linux
Stacer - System Optimizer And Monitoring Tool For Linux
HackerSploit
50 Kali Linux 2018.1 - Kernel Updates & Patches
Kali Linux 2018.1 - Kernel Updates & Patches
HackerSploit
51 MITM With Ettercap - ARP Poisoning
MITM With Ettercap - ARP Poisoning
HackerSploit
52 Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
Password Cracking With John The Ripper - RAR/ZIP & Linux Passwords
HackerSploit
53 How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
How To Detect Rootkits On Kali Linux - chkrootkit & rkhunter
HackerSploit
54 Channel Updates - How To Post Questions & Video Suggestions
Channel Updates - How To Post Questions & Video Suggestions
HackerSploit
55 Web App Penetration Testing - #1 - Setting Up Burp Suite
Web App Penetration Testing - #1 - Setting Up Burp Suite
HackerSploit
56 Web App Penetration Testing - #2 - Spidering & DVWA
Web App Penetration Testing - #2 - Spidering & DVWA
HackerSploit
57 Cl0neMast3r - GitHub Repository Cloning Tool
Cl0neMast3r - GitHub Repository Cloning Tool
HackerSploit
58 Kali Linux On Windows 10 Official - WSL - Installation & Configuration
Kali Linux On Windows 10 Official - WSL - Installation & Configuration
HackerSploit
59 DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
DoS/DDoS Protection - How To Enable ICMP, UDP & TCP Flood Filtering
HackerSploit
60 Web App Penetration Testing - #3 - Brute Force With Burp Suite
Web App Penetration Testing - #3 - Brute Force With Burp Suite
HackerSploit

This video teaches how to optimize Nmap scans for better performance and timing, which is essential for efficient network scanning and discovery. By adjusting parameters such as timing templates, parallelism, and packet rate, users can improve the speed and accuracy of their scans.

Key Takeaways
  1. Adjust timing templates to suit the network environment
  2. Configure parallelism for faster scans
  3. Optimize host group sizes for efficient scanning
  4. Set host timeout to avoid waiting for unresponsive hosts
  5. Configure scan delay to control the speed of scans
  6. Adjust packet rate to optimize scan performance
💡 Optimizing Nmap scans using the right timing and performance parameters can significantly improve the efficiency and accuracy of network scanning and discovery.

Related Reads

Chapters (6)

Intro
9:05 Parallelism
14:08 Host Group Sizes
18:25 Host Timeout
23:10 Scan Delay
26:13 Packet Rate
Up next
NordVPN Coupon Code 2026 | Exclusive Discount + 4 FREE Months
Tutorial Stack
Watch →