Pick your target, port range, scan type, timing and NSE scripts. This generator assembles the precise, copy-ready Nmap command line for recon during authorized bug bounty and pentest work.
nmap …
Every flag is assembled in canonical Nmap order: nmap [scan type] [host disc] [-pPORTS] [-T#] [detection] [--script] [-oA] TARGET. The tool also computes a rough noise score so you can judge how detectable a scan is before you run it on a live program scope.
The noise estimate uses a simple additive model. Each timing template contributes points equal to its number (T0=0 … T5=5), because faster timing fires probes in tighter bursts that trip rate-based IDS rules. Loud scan types add weight: -sT (full connect, logged by the app) adds 3, -sV adds 2 for its banner probes, -A adds 4, and -O adds 1. Stealth types like -sS, -sF and -sA add 0 because they never complete the TCP handshake. The script then maps the total to a band: 0–3 = Stealthy, 4–7 = Moderate, 8+ = Loud. The formula is noise = T + typeWeight + sum(optionWeights).
It also flags the privilege requirement. Raw-packet scans (-sS, -sU, -sF, -sA, -O) need root or CAP_NET_RAW, while -sT connect scans run as any user because they use the normal sockets API. Knowing this up front saves the classic "you requested a scan type which requires root privileges" error mid-engagement. Port count is parsed from your range to remind you that wide UDP sweeps are slow: a full -sU -p1-65535 against one host can take hours under polite timing, so the tool nudges you toward targeted ports. Use the result only against hosts you are explicitly authorized to test under a bug bounty scope or written engagement.