Network Services

Scan Networks with Nmap and cnspec

Discover hosts, open ports, and services using Nmap with cnspec.

Discover hosts, open ports, and running services across your network with cnspec and the Nmap network scanner. Use the Nmap provider inside your own policies to check exposure, for example asserting that no host listens on Telnet or that SSH is reachable only from specific subnets.

Nmap is one of several ways cnspec scans networks and hosts. For the full list, see the networks and hosts overview. New to cnspec? Start with the quickstart.

Prerequisites

To scan networks with cnspec and Nmap, you must have:

Scan a network or host

Open a cnspec shell to scan a single host with the host sub-command:

cnspec shell nmap host 192.168.1.1

Scan a domain and the hosts behind it with the domain sub-command:

cnspec shell nmap domain example.com

Scan one or more network ranges in CIDR notation with --networks:

cnspec shell nmap --networks 10.0.0.0/8,192.168.0.0/16

To scan each host that Nmap discovers in those networks as its own asset, add --discover hosts:

cnspec scan nmap --networks 192.168.1.0/24 --discover hosts

Connection options

OptionDescription
--networksComma-separated list of networks to scan, for example 10.0.0.0/8,192.168.0.0/16
--portsPorts to scan, for example 22,80,443 or 1-1024

Example queries

List all discovered hosts

nmap.network takes the network to scan as its target:

cnspec> nmap.network(target: "192.168.1.0/24").hosts
nmap.network.hosts: [
  0: name="192.168.1.1"
  1: name="192.168.1.100"
  ...
]

Retrieve the Nmap version

cnspec> nmap.version
version: version="7.97"

Find all hosts with open SSH ports

cnspec> nmap.network(target: "192.168.1.0/24").hosts.where(ports.any(port == 22 && state == "open"))

List all open ports across all hosts

cnspec> nmap.network(target: "192.168.1.0/24").hosts { name ports.where(state == "open") { port protocol service } }

Learn more

On this page