> For the complete documentation index, see [llms.txt](https://notes.cavementech.com/pentesting-quick-reference/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.cavementech.com/pentesting-quick-reference/host-discovery.md).

# Host Discovery

## NMAP Host discovery

```
nmap -sn -PR 192.168.18.110
```

{% hint style="info" %}
-sn disables port scan

-PR arp scan on host
{% endhint %}

other nmap scans to discover host.

```
sudo nmap -sn -PU 192.168.18.110   //UDP ping scan
nmap -sn -PE 192.168.18.110   //ICMP ping scan. Normal ping scan
nmap -sn -PE 192.168.18.1-255   //check live hosts on network range
nmap -sn -PM 192.168.18.1-255    //Mask Ping scan (use if ICMP is blocked)
nmap -sn -PP 192.168.18.1-255    //ICMP timestamp scan
nmap -sn -PS 192.168.18.1-255    //tcp syn ping scan
nmap -sn -PO 192.168.18.1-255     //IP protocol scan.use different protocols to test the connectivity
```
