Nmap Scripting Engine (NSE)
NSE scripts extend Nmap with vulnerability detection, brute-forcing, and deeper discovery beyond what port scanning alone provides. Run scripts with --script (by name, category, or wildcard) and --script-help for per-script documentation.
Categories
auth— Authentication probing and bypassesbroadcast— Broadcast probesbrute— Brute-force attacksdefault— Curated, fast, reliable scripts (-sC)discovery— Additional info gatheringdos— May crash servicesexploit— Active exploitationexternal— Sends data to third partiesfuzzer— Fuzzingintrusive— Noisy / riskymalware— Malware detectionsafe— Low riskversion— Called by-sV(cannot be called directly)vuln— Vulnerability checks (prone to false positives)
Targeted reconnaissance
SMB/CIFS
nmap -vv -sT \
--script smb-enum-shares.nse,smb-enum-users.nse \
-p445 $TARGET_IPGotcha:
smb-enum-users.nseis Windows-specific — against UNIX-like hosts running Samba it typically returns no users. Fall back to enum4linux (RID cycling) or smbmap for user enumeration on Samba targets. 1
Vulnerability scanning with vulners
The stock vuln NSE category runs built-in vulnerability checks. For per-service CVE matching against the vulners.com database, install the third-party vulners.nse script into Nmap’s script directory; it then runs as part of --script vuln output (shown as a vulners: block per port, keyed off detected CPEs). The CVE list is version-based only — treat hits as leads, not confirmations, since backported patches (common on Ubuntu/Debian) produce false positives. 2
NFS
nmap -v -sT --script nfs-ls,nfs-statfs,nfs-showmount \
-p$PORT $IPRelated
- nmap — the parent Nmap reference (scan types, host discovery, flags)
- nmap-port-selection — which ports Nmap scans and why
- nbtscan — lightweight NetBIOS name-service scanner that complements Nmap’s
nbstat.nse - nfs —
showmount/ rpcbind enumeration pairs with Nmap’snfs-*scripts