Scan Networks with Nmap and cnspec
Discover hosts, open ports, and services using Nmap with cnspec.
Discover hosts, open ports, and running services across your network with cnspec and the Nmap network scanner. Use the Nmap provider inside your own policies to check exposure, for example asserting that no host listens on Telnet or that SSH is reachable only from specific subnets.
Nmap is one of several ways cnspec scans networks and hosts. For the full list, see the networks and hosts overview. New to cnspec? Start with the quickstart.
Prerequisites
To scan networks with cnspec and Nmap, you must have:
Scan a network or host
Open a cnspec shell to scan a single host with the host sub-command:
cnspec shell nmap host 192.168.1.1Scan a domain and the hosts behind it with the domain sub-command:
cnspec shell nmap domain example.comScan one or more network ranges in CIDR notation with --networks:
cnspec shell nmap --networks 10.0.0.0/8,192.168.0.0/16To scan each host that Nmap discovers in those networks as its own asset, add --discover hosts:
cnspec scan nmap --networks 192.168.1.0/24 --discover hostsConnection options
| Option | Description |
|---|---|
--networks | Comma-separated list of networks to scan, for example 10.0.0.0/8,192.168.0.0/16 |
--ports | Ports to scan, for example 22,80,443 or 1-1024 |
Example queries
List all discovered hosts
nmap.network takes the network to scan as its target:
cnspec> nmap.network(target: "192.168.1.0/24").hosts
nmap.network.hosts: [
0: name="192.168.1.1"
1: name="192.168.1.100"
...
]Retrieve the Nmap version
cnspec> nmap.version
version: version="7.97"Find all hosts with open SSH ports
cnspec> nmap.network(target: "192.168.1.0/24").hosts.where(ports.any(port == 22 && state == "open"))List all open ports across all hosts
cnspec> nmap.network(target: "192.168.1.0/24").hosts { name ports.where(state == "open") { port protocol service } }Learn more
- Nmap Resource Pack Reference: every Nmap resource and field cnspec can query
- Write Effective MQL: guide to authoring checks and queries