Naabu

APIyesOSS—FREEyesDOCS5/5
NA7.4#1 of 25
—WeboutWindowsoutMacoutLinux—Android—iOS

Ranked in Port Scanner Software ·Free plan

About

Naabu is a free command-line port scanner for attack-surface discovery in bug-bounty work and penetration tests. It probes hosts with SYN, CONNECT, and UDP scans, accepting hosts, IPs, CIDRs, and ASNs directly, from files, or through standard input. Results can be emitted as JSON, CSV, text, or standard output. IPv4 scanning is supported; IPv6 and host discovery are marked experimental. Passive enumeration can use Shodan InternetDB, and DNS port scans are available. Naabu can identify services by port and use Nmap service probes for version detection; that detection requires a service-probe database from a local Nmap installation or a custom path. Discovered ports can be piped to ProjectDiscovery's httpx to identify running HTTP servers. Its CLI can upload or display results in the ProjectDiscovery Cloud dashboard, including association with team and asset IDs. Installation options include ready-to-run binaries, Docker, and Go. Packet capture requires libpcap on Linux and macOS or Npcap on Windows; the README recommends root privileges and tuning scan flags and rates for local systems.

Who it is for

Naabu suits security practitioners mapping attack surfaces for bug-bounty work and penetration tests. Its CLI, varied inputs, and pipeline integrations fit workflows that combine scanning with other tools.

What is good

  • Supports SYN, CONNECT, and UDP probes
  • Accepts hosts, IPs, CIDRs, and ASNs
  • Exports JSON, CSV, text, or standard output
  • Can send discovered ports to httpx

What to know first

  • IPv6 and host discovery are experimental
  • Packet capture requires libpcap or Npcap
  • Service version detection needs an Nmap probe database

Inferse review

Naabu: the full review

Naabu offers free port scanning with multiple input and output options, plus Nmap and httpx integration. Account for its packet-capture prerequisites and the external database needed for service version detection.

Overview

Naabu is a free command-line port scanner for operators who need to fold host and port discovery into an existing security workflow. It suits bug-bounty and penetration-testing teams comfortable with CLI tooling; its main trade-off is operational setup, including packet-capture dependencies and elevated privileges for best results.

With multiple scan methods, target inputs and export formats, Naabu is a practical fit for scripted internet-scope discovery. It is less suitable for teams that want a managed graphical scanner or service-version detection without supplying a separate Nmap probe database.

Key features

Scanning and target control

Naabu supports SYN, CONNECT and UDP probing, plus DNS port scanning. Targets can be hosts, IPs, CIDRs or ASNs, entered directly, loaded from a file or passed through standard input. That flexibility helps teams feed inventories into a repeatable CLI process rather than re-entering targets for each scan.

IPv4 scanning is supported, while IPv6 and host discovery are marked experimental. Those capabilities may be useful for exploration, but teams relying on stable coverage should treat them as less mature than the core scan methods. Passive enumeration can use Shodan InternetDB. CDN/WAF exclusion can restrict scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula and Sucuri IPs, a useful guardrail when broad scans could otherwise reach protected infrastructure.

Service discovery and workflow integration

Naabu integrates with Nmap for service discovery and additional scans. It can identify services by port and detect versions using Nmap service probes, but the service-probe database is not bundled: version detection requires a local Nmap installation or a custom database path. That makes the integration useful for teams already running Nmap, but adds setup for anyone expecting a self-contained scanner.

Discovered ports can be piped to httpx to identify running HTTP servers. Output is available as JSON, CSV, text or standard output, so results can move into scripts and adjacent tools without being confined to a single report format. The CLI can also upload or display results in the ProjectDiscovery Cloud dashboard and associate them with team and asset IDs.

Installation and operation

ProjectDiscovery provides ready-to-run binaries, Docker installation and Go installation. Packet capture requires libpcap on Linux and macOS or Npcap on Windows. The README recommends running Naabu as root for best results and tuning flags and scan rate on local systems. These requirements are manageable for security teams accustomed to scanner setup, but less convenient than a hosted service with no local prerequisites.

Naabu's README places responsibility for scanning activity on the user and disclaims developer liability for misuse or damage; operators should keep scans within authorized scope.

Pricing

Naabu is free under its Open source plan at 0.00 USD per free. The plan is MIT-licensed and provides the port-scanning tool as a CLI, with internet scan scope, API access and JSON, CSV, TXT and STDOUT export formats. There is no paid Naabu tier to trade features or quotas against; teams should instead account for the local installation and service-detection database requirements.

Platforms

Naabu is available for Linux, macOS and Windows, with self-hosted deployment and API access. Its CLI orientation makes it a natural fit for teams that already manage command-line security tooling; it is not a web-based scanning interface.

Who it's for

Naabu is best suited to bug-bounty operators and penetration testers building attack-surface discovery pipelines, especially those who already use Nmap or ProjectDiscovery's httpx. Its varied inputs and machine-readable outputs support integration into existing workflows. Teams seeking a guided web interface, or unwilling to manage packet capture and privileges, should look at hosted alternatives instead.

Pros and cons

  • Pros: SYN, CONNECT and UDP scans plus broad host, IP, CIDR and ASN inputs give operators flexibility in how they define targets.
  • Pros: JSON, CSV, text and standard output, along with Nmap and httpx integration, make results usable in multi-tool discovery pipelines.
  • Pros: Free, MIT-licensed availability avoids a product subscription for the scanner itself.
  • Cons: Packet capture dependencies and the recommendation to run as root add setup and operational care.
  • Cons: Service-version detection depends on an external Nmap probe database, so it is not turnkey.
  • Cons: IPv6 scanning and host discovery are experimental, limiting their suitability for workflows that need mature behavior.

Alternatives

Port Scanner Software is the broader category directory for comparing other options.

  • ScanSearch is worth considering when a freemium scanner with Linux and web access, a free trial and a paid internet-scanning plan is a better fit; its Internet Scanner plan is 0.30 USD per month, billed per kpps/month.
  • Pentest-Tools Port Scanner may suit teams preferring API and web access with a free tier and trial; its NetSec plan starts at 95.00 USD per month.
  • Unicornscan is another free, GPL port-scanning option for Linux, macOS, self-hosted and web use.
  • HostedScan Security is a paid API and web option with a free trial, suited to buyers willing to pay for its Basic plan at 39.00 USD per month.
  • Nmap is a free alternative for Linux, macOS, self-hosted and Windows; its end-user license does not allow redistribution within commercial software or hardware products.
  • Angry IP Scanner is a free, GPLv2 option for Linux, macOS and Windows.
  • RustScan is a free open-source scanner for Linux, macOS, Windows, Android and self-hosted use.
  • Nmap Online Scan is a web-based alternative with a freemium model and a free trial.

Verdict

Choose Naabu if your team needs a free, scriptable port scanner that can feed Nmap and httpx workflows. Its combination of scan methods, target inputs and export formats is compelling for attack-surface discovery, but local packet-capture setup and the external Nmap database make it a weaker choice for teams wanting a ready-to-use hosted scanner or self-contained service-version detection.

Compared on port scanner software

Free plan
Yesgithub.com
Deployment
cligithub.com
Scan scope
internetgithub.com
Service detection
Yesgithub.com
API access
Yesgithub.com
Export formats
JSON, CSV, TXT, STDOUTgithub.com

Facts

Purpose
Naabu is a Go port-scanning tool that enumerates valid ports on hosts using SYN, CONNECT, and UDP scans.github.com · 1 Oct 2026
Scanning
It supports fast SYN, CONNECT, and UDP probe-based scanning.github.com · 1 Oct 2026
Inputs
It accepts STDIN, hosts, IPs, CIDRs, and ASNs as scan inputs.github.com · 1 Oct 2026
Outputs
It supports JSON, TXT, and standard-output formats.github.com · 1 Oct 2026
IPv4 and IPv6
IPv4 and IPv6 port scanning is supported, with IPv6 marked experimental in the feature list.github.com · 1 Oct 2026
Passive enumeration
Passive port enumeration can use Shodan InternetDB.github.com · 1 Oct 2026
Host discovery
Host discovery scanning is available and marked experimental.github.com · 1 Oct 2026
Nmap integration
Naabu integrates with Nmap for service discovery and additional scans.github.com · 1 Oct 2026
Cloud dashboard
The CLI can upload or display scan output in the ProjectDiscovery Cloud dashboard and can associate results with team and asset IDs.github.com · 1 Oct 2026
CDN and WAF exclusion
CDN/WAF exclusion can limit scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula, and Sucuri IPs.github.com · 1 Oct 2026
Installation
The maker provides ready-to-run binaries, Docker installation, and Go installation.github.com · 1 Oct 2026
Platform prerequisites
Packet capture requires libpcap on Linux and macOS or Npcap on Windows.github.com · 1 Oct 2026
Operational requirement
The README recommends running Naabu as root for best results and tuning flags and scan rate on local systems.github.com · 1 Oct 2026
Pipeline integration
Discovered ports can be piped to httpx to identify running HTTP servers.github.com · 1 Oct 2026
Audience
ProjectDiscovery describes Naabu as designed for attack-surface discovery in bug-bounty work and penetration tests.github.com · 1 Oct 2026
Support
ProjectDiscovery directs users to GitHub and Discord for help with its open-source tools.github.com · 1 Oct 2026
Safety notice
The Naabu README says users are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 1 Oct 2026
Scan types
It supports SYN, CONNECT and UDP scans.github.com · 2 Oct 2026
Host inputs
Inputs can include hosts, IPs, CIDRs and ASNs, supplied directly, from a file or through standard input.github.com · 2 Oct 2026
Discovery
Features include DNS port scanning, experimental host discovery, IPv4/IPv6 scanning and passive port enumeration using Shodan InternetDB.github.com · 2 Oct 2026
Integrations
It integrates with Nmap for service discovery and can pipe discovered ports to ProjectDiscovery's httpx tool.github.com · 2 Oct 2026
Cloud integration
CLI options can upload or view scan output in the ProjectDiscovery Cloud dashboard.github.com · 2 Oct 2026
Output formats
It supports JSON, CSV, text and standard output.github.com · 2 Oct 2026
Installation requirement
The installation instructions require libpcap for packet capture; they name Linux, macOS and Windows installation options.github.com · 2 Oct 2026
Service probe limit
Naabu does not include the Nmap service probe database, so service version detection requires that database from a local Nmap installation or a custom path.github.com · 2 Oct 2026
Security notice
The README warns users that they are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 2 Oct 2026
Intended users
The README describes Naabu as designed to work with other tools for attack surface discovery in bug bounties and penetration tests.github.com · 2 Oct 2026

Best Naabu alternatives

See all 12

Where it ranks on Inferse

Sources