Naabu
Ranked in Port Scanner Software ·Free plan
About
Naabu is a free command-line port scanner for attack-surface discovery in bug-bounty work and penetration tests. It probes hosts with SYN, CONNECT, and UDP scans, accepting hosts, IPs, CIDRs, and ASNs directly, from files, or through standard input. Results can be emitted as JSON, CSV, text, or standard output. IPv4 scanning is supported; IPv6 and host discovery are marked experimental. Passive enumeration can use Shodan InternetDB, and DNS port scans are available. Naabu can identify services by port and use Nmap service probes for version detection; that detection requires a service-probe database from a local Nmap installation or a custom path. Discovered ports can be piped to ProjectDiscovery's httpx to identify running HTTP servers. Its CLI can upload or display results in the ProjectDiscovery Cloud dashboard, including association with team and asset IDs. Installation options include ready-to-run binaries, Docker, and Go. Packet capture requires libpcap on Linux and macOS or Npcap on Windows; the README recommends root privileges and tuning scan flags and rates for local systems.
Who it is for
Naabu suits security practitioners mapping attack surfaces for bug-bounty work and penetration tests. Its CLI, varied inputs, and pipeline integrations fit workflows that combine scanning with other tools.
What is good
- Supports SYN, CONNECT, and UDP probes
- Accepts hosts, IPs, CIDRs, and ASNs
- Exports JSON, CSV, text, or standard output
- Can send discovered ports to httpx
What to know first
- IPv6 and host discovery are experimental
- Packet capture requires libpcap or Npcap
- Service version detection needs an Nmap probe database
Inferse review
Naabu: the full review
Naabu offers free port scanning with multiple input and output options, plus Nmap and httpx integration. Account for its packet-capture prerequisites and the external database needed for service version detection.
Overview
Naabu is a free command-line port scanner for operators who need to fold host and port discovery into an existing security workflow. It suits bug-bounty and penetration-testing teams comfortable with CLI tooling; its main trade-off is operational setup, including packet-capture dependencies and elevated privileges for best results.
With multiple scan methods, target inputs and export formats, Naabu is a practical fit for scripted internet-scope discovery. It is less suitable for teams that want a managed graphical scanner or service-version detection without supplying a separate Nmap probe database.
Key features
Scanning and target control
Naabu supports SYN, CONNECT and UDP probing, plus DNS port scanning. Targets can be hosts, IPs, CIDRs or ASNs, entered directly, loaded from a file or passed through standard input. That flexibility helps teams feed inventories into a repeatable CLI process rather than re-entering targets for each scan.
IPv4 scanning is supported, while IPv6 and host discovery are marked experimental. Those capabilities may be useful for exploration, but teams relying on stable coverage should treat them as less mature than the core scan methods. Passive enumeration can use Shodan InternetDB. CDN/WAF exclusion can restrict scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula and Sucuri IPs, a useful guardrail when broad scans could otherwise reach protected infrastructure.
Service discovery and workflow integration
Naabu integrates with Nmap for service discovery and additional scans. It can identify services by port and detect versions using Nmap service probes, but the service-probe database is not bundled: version detection requires a local Nmap installation or a custom database path. That makes the integration useful for teams already running Nmap, but adds setup for anyone expecting a self-contained scanner.
Discovered ports can be piped to httpx to identify running HTTP servers. Output is available as JSON, CSV, text or standard output, so results can move into scripts and adjacent tools without being confined to a single report format. The CLI can also upload or display results in the ProjectDiscovery Cloud dashboard and associate them with team and asset IDs.
Installation and operation
ProjectDiscovery provides ready-to-run binaries, Docker installation and Go installation. Packet capture requires libpcap on Linux and macOS or Npcap on Windows. The README recommends running Naabu as root for best results and tuning flags and scan rate on local systems. These requirements are manageable for security teams accustomed to scanner setup, but less convenient than a hosted service with no local prerequisites.
Naabu's README places responsibility for scanning activity on the user and disclaims developer liability for misuse or damage; operators should keep scans within authorized scope.
Pricing
Naabu is free under its Open source plan at 0.00 USD per free. The plan is MIT-licensed and provides the port-scanning tool as a CLI, with internet scan scope, API access and JSON, CSV, TXT and STDOUT export formats. There is no paid Naabu tier to trade features or quotas against; teams should instead account for the local installation and service-detection database requirements.
Platforms
Naabu is available for Linux, macOS and Windows, with self-hosted deployment and API access. Its CLI orientation makes it a natural fit for teams that already manage command-line security tooling; it is not a web-based scanning interface.
Who it's for
Naabu is best suited to bug-bounty operators and penetration testers building attack-surface discovery pipelines, especially those who already use Nmap or ProjectDiscovery's httpx. Its varied inputs and machine-readable outputs support integration into existing workflows. Teams seeking a guided web interface, or unwilling to manage packet capture and privileges, should look at hosted alternatives instead.
Pros and cons
- Pros: SYN, CONNECT and UDP scans plus broad host, IP, CIDR and ASN inputs give operators flexibility in how they define targets.
- Pros: JSON, CSV, text and standard output, along with Nmap and httpx integration, make results usable in multi-tool discovery pipelines.
- Pros: Free, MIT-licensed availability avoids a product subscription for the scanner itself.
- Cons: Packet capture dependencies and the recommendation to run as root add setup and operational care.
- Cons: Service-version detection depends on an external Nmap probe database, so it is not turnkey.
- Cons: IPv6 scanning and host discovery are experimental, limiting their suitability for workflows that need mature behavior.
Alternatives
Port Scanner Software is the broader category directory for comparing other options.
- ScanSearch is worth considering when a freemium scanner with Linux and web access, a free trial and a paid internet-scanning plan is a better fit; its Internet Scanner plan is 0.30 USD per month, billed per kpps/month.
- Pentest-Tools Port Scanner may suit teams preferring API and web access with a free tier and trial; its NetSec plan starts at 95.00 USD per month.
- Unicornscan is another free, GPL port-scanning option for Linux, macOS, self-hosted and web use.
- HostedScan Security is a paid API and web option with a free trial, suited to buyers willing to pay for its Basic plan at 39.00 USD per month.
- Nmap is a free alternative for Linux, macOS, self-hosted and Windows; its end-user license does not allow redistribution within commercial software or hardware products.
- Angry IP Scanner is a free, GPLv2 option for Linux, macOS and Windows.
- RustScan is a free open-source scanner for Linux, macOS, Windows, Android and self-hosted use.
- Nmap Online Scan is a web-based alternative with a freemium model and a free trial.
Verdict
Choose Naabu if your team needs a free, scriptable port scanner that can feed Nmap and httpx workflows. Its combination of scan methods, target inputs and export formats is compelling for attack-surface discovery, but local packet-capture setup and the external Nmap database make it a weaker choice for teams wanting a ready-to-use hosted scanner or self-contained service-version detection.
Compared on port scanner software
- Free plan
- Yesgithub.com
- Deployment
- cligithub.com
- Scan scope
- internetgithub.com
- Service detection
- Yesgithub.com
- API access
- Yesgithub.com
- Export formats
- JSON, CSV, TXT, STDOUTgithub.com
Facts
- Purpose
- Naabu is a Go port-scanning tool that enumerates valid ports on hosts using SYN, CONNECT, and UDP scans.github.com · 1 Oct 2026
- Scanning
- It supports fast SYN, CONNECT, and UDP probe-based scanning.github.com · 1 Oct 2026
- Inputs
- It accepts STDIN, hosts, IPs, CIDRs, and ASNs as scan inputs.github.com · 1 Oct 2026
- Outputs
- It supports JSON, TXT, and standard-output formats.github.com · 1 Oct 2026
- IPv4 and IPv6
- IPv4 and IPv6 port scanning is supported, with IPv6 marked experimental in the feature list.github.com · 1 Oct 2026
- Passive enumeration
- Passive port enumeration can use Shodan InternetDB.github.com · 1 Oct 2026
- Host discovery
- Host discovery scanning is available and marked experimental.github.com · 1 Oct 2026
- Nmap integration
- Naabu integrates with Nmap for service discovery and additional scans.github.com · 1 Oct 2026
- Cloud dashboard
- The CLI can upload or display scan output in the ProjectDiscovery Cloud dashboard and can associate results with team and asset IDs.github.com · 1 Oct 2026
- CDN and WAF exclusion
- CDN/WAF exclusion can limit scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula, and Sucuri IPs.github.com · 1 Oct 2026
- Installation
- The maker provides ready-to-run binaries, Docker installation, and Go installation.github.com · 1 Oct 2026
- Platform prerequisites
- Packet capture requires libpcap on Linux and macOS or Npcap on Windows.github.com · 1 Oct 2026
- Operational requirement
- The README recommends running Naabu as root for best results and tuning flags and scan rate on local systems.github.com · 1 Oct 2026
- Pipeline integration
- Discovered ports can be piped to httpx to identify running HTTP servers.github.com · 1 Oct 2026
- Audience
- ProjectDiscovery describes Naabu as designed for attack-surface discovery in bug-bounty work and penetration tests.github.com · 1 Oct 2026
- Support
- ProjectDiscovery directs users to GitHub and Discord for help with its open-source tools.github.com · 1 Oct 2026
- Safety notice
- The Naabu README says users are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 1 Oct 2026
- Scan types
- It supports SYN, CONNECT and UDP scans.github.com · 2 Oct 2026
- Host inputs
- Inputs can include hosts, IPs, CIDRs and ASNs, supplied directly, from a file or through standard input.github.com · 2 Oct 2026
- Discovery
- Features include DNS port scanning, experimental host discovery, IPv4/IPv6 scanning and passive port enumeration using Shodan InternetDB.github.com · 2 Oct 2026
- Integrations
- It integrates with Nmap for service discovery and can pipe discovered ports to ProjectDiscovery's httpx tool.github.com · 2 Oct 2026
- Cloud integration
- CLI options can upload or view scan output in the ProjectDiscovery Cloud dashboard.github.com · 2 Oct 2026
- Output formats
- It supports JSON, CSV, text and standard output.github.com · 2 Oct 2026
- Installation requirement
- The installation instructions require libpcap for packet capture; they name Linux, macOS and Windows installation options.github.com · 2 Oct 2026
- Service probe limit
- Naabu does not include the Nmap service probe database, so service version detection requires that database from a local Nmap installation or a custom path.github.com · 2 Oct 2026
- Security notice
- The README warns users that they are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 2 Oct 2026
- Intended users
- The README describes Naabu as designed to work with other tools for attack surface discovery in bug bounties and penetration tests.github.com · 2 Oct 2026
Best Naabu alternatives
See all 12Where it ranks on Inferse
Sources
- github.com/projectdiscovery/naabu/blob/dev/README.· checked 1 Oct 2026
- github.com/projectdiscovery· checked 1 Oct 2026
- github.com/projectdiscovery/naabu· checked 2 Oct 2026


