Nmap Port Selection and nmap-services
How Nmap decides which ports to scan — the default top-1,000 behavior, the empirical frequency rankings behind it, and how to query or override the selection.
Top ports
By default, Nmap scans the top 1,000 ports for each protocol requested. This catches roughly 93% of open TCP ports and 49% of open UDP ports. -F (fast scan) scans only the top 100 ports (78% TCP, 39% UDP). To scan a different number, use --top-ports N. 1
The nmap-services file
The port rankings come from the nmap-services file — a registry of port names, numbers, protocols, and an empirical “port frequency” score measuring how often each port was found open during large-scale Internet scans. The file lives at /usr/share/nmap/nmap-services on most Linux systems. 2
To see the ports ranked by frequency (most common first):
sort -r -k3 /usr/share/nmap/nmap-servicesTo list the top N ports that Nmap would actually scan (e.g., top 100 TCP):
nmap -sT --top-ports 100 -v -oG -Or to see all 1,000 defaults: nmap -sT --top-ports 1000 -v -oG - (same for UDP with -sU). 3
Coverage effectiveness
TCP vs UDP ports needed to reach a given coverage rate:
| Coverage | TCP ports | UDP ports |
|---|---|---|
| 50% | 10 | 1,075 |
| 80% | 122 | 7,981 |
| 90% | 576 | 11,307 |
| 95% | 1,558 | 13,035 |
| 99% | 3,328 | 15,094 |
The takeaway: TCP scanning is efficient (a few hundred ports covers most of what is open), while UDP scanning requires an order of magnitude more ports for equivalent coverage — one reason UDP scans are so slow in practice.
The top 5 TCP ports by frequency: HTTP (80), telnet (23), HTTPS (443), FTP (21), SSH (22). The top 5 UDP ports: IPP (631), SNMP (161), NetBIOS-NS (137), NTP (123), NetBIOS-DGM (138). 5
Related
- nmap — the parent Nmap reference (scan types, host discovery, flags)
- nmap-nse — NSE scripts for service-level recon on the ports found
- bash-port-scanning — zero-binary alternative when Nmap isn’t available
- arp-scanning — layer-2 host discovery complement