Free Nmap Penetration Testing Lab: Practice Network Scanning in Your Browser
Network reconnaissance is one of the fundamental skills used in cybersecurity, penetration testing, system administration, and security auditing.
Before assessing the security of a system, you first need to understand what is actually exposed: which hosts are online, which ports are open, what services are running, and what information those services reveal.
Nmap is one of the most widely used tools for this job.
To help learners practice these concepts without setting up a complete virtual lab, CertInstructor provides the Nmap Penetration Testing Lab, a free browser-based interactive training environment.
Launch the lab:
https://go.certinstructor.org/labs/nmap/
The lab simulates a Kali Linux attacker system communicating with a deliberately vulnerable Metasploitable 2 target. Everything runs inside a simulated learning environment, so you can experiment with Nmap commands without scanning real systems.
What Is the CertInstructor Nmap Lab?
The Nmap Lab is designed to teach the basic workflow of network reconnaissance and vulnerability assessment through interactive practice.
Instead of only memorizing Nmap commands, you can enter commands in a simulated terminal, observe realistic scan results, discover services, complete practical missions, and test your knowledge.
The lab is organized into four main areas:
-
Lab Guide — understand Nmap, the simulated network, and the most important commands.
-
Terminal Lab — execute Nmap commands against the simulated target.
-
Scenario Missions — complete four practical reconnaissance objectives.
-
Knowledge Check — finish with a 10-question assessment.
This progression takes you from understanding the tool to actually using its syntax and interpreting scan results.
Lab Architecture
The simulated environment contains two systems.
Attacker
Kali Linux
IP address: 10.10.10.10
This represents the security testing workstation where Nmap commands are executed.
Target
Metasploitable 2
IP address: 10.10.10.11
Metasploitable is used here as the intentionally vulnerable target system.
The basic lab workflow is therefore:
Kali Linux → Nmap Probes → Target → Scan Results
Because this is a simulator, no real external system is scanned.
What Can Nmap Tell You?
Nmap — short for Network Mapper — can help answer several important questions during authorized security testing.
Host Discovery
Before examining individual services, you may first need to determine which systems are active on a network.
Nmap can help identify reachable hosts and provide a starting point for further investigation.
Port Scanning
Network services listen on ports.
A scan may reveal ports associated with services such as:
-
SSH
-
HTTP
-
HTTPS
-
FTP
-
SMTP
-
DNS
-
SMB
-
Databases
-
Remote administration services
Finding an open port does not automatically mean a vulnerability exists. It tells you that a service may be available and deserves further investigation.
Service Detection
Knowing that a port is open is only the beginning.
Nmap can attempt to determine which software and service version is listening on that port.
In the lab, try:
nmap -sV <target>
Service information can help security professionals understand the attack surface and identify software that may require additional security review.
Operating System Detection
Nmap can also attempt to fingerprint a remote operating system.
Try:
nmap -O <target>
OS fingerprinting analyzes characteristics of network responses and uses them to estimate which operating system the target may be running.
Nmap Scripting Engine
The Nmap Scripting Engine, commonly called NSE, extends Nmap far beyond basic port scanning.
Scripts can assist with tasks such as:
-
Service enumeration
-
Configuration auditing
-
Authentication checks
-
Information gathering
-
Vulnerability detection
The CertInstructor lab includes examples that introduce this capability in a controlled environment.
Quick Nmap Command Reference
The Lab Guide includes several useful commands that you can practice directly in the simulator.
Basic Scan
nmap <target>
Runs a standard scan against the target and checks commonly used ports.
For this lab, the simulated target is:
10.10.10.11
SYN Scan
nmap -sS <target>
Performs a TCP SYN scan.
This is one of the most commonly used Nmap scan types during authorized network reconnaissance.
Service Version Detection
nmap -sV <target>
Attempts to identify services and their versions.
This is especially useful after discovering open ports because it gives you more context about what is actually running.
Operating System Detection
nmap -O <target>
Attempts to identify the target operating system.
Aggressive Detection
nmap -A <target>
Enables several discovery features together, including operating-system detection, service/version detection, scripts, and traceroute-related information.
Because this option performs more probing than a basic scan, it is particularly useful in a controlled training environment where you want to examine detailed results.
Scan All TCP Ports
nmap -p- <target>
Requests a scan across all 65,535 TCP ports rather than only the commonly scanned ports.
This demonstrates an important lesson in reconnaissance: a service may be listening on an unexpected port.
Vulnerability Detection Scripts
nmap --script vuln <target>
Uses NSE scripts associated with vulnerability detection.
The results can provide leads for additional investigation, but automated output should always be interpreted carefully rather than treated as absolute proof of a vulnerability.
Authentication-Related Scripts
nmap --script auth <target>
Runs NSE scripts associated with authentication-related checks.
These examples demonstrate why NSE is such a powerful extension to standard network scanning.
How to Use the Terminal Lab
Open the Terminal Lab after reviewing the Lab Guide.
You will see a terminal representing:
student@kali
The target system is available at:
10.10.10.11
Start with a simple scan:
nmap 10.10.10.11
Study the result before moving on.
Ask yourself:
Which ports are open?
Which services may be running?
Which services deserve further investigation?
Then add additional options.
For example:
nmap -sV 10.10.10.11
Compare this output with the basic scan.
Next you might experiment with:
nmap -O 10.10.10.11
or:
nmap -A 10.10.10.11
The goal is not simply to execute commands.
The important part is learning how each option changes the information returned by Nmap.
Use the Command Hints
The simulator includes command hints to help you get started.
If you are new to Nmap, use these shortcuts to experiment with common syntax before typing commands manually.
As you become more comfortable, try entering the commands yourself.
A useful learning pattern is:
Run → Observe → Compare → Interpret
Run a scan.
Observe the output.
Change one option.
Compare the new result.
Then determine what additional information the new scan provided.
This is much more effective than simply memorizing a list of command-line switches.
Complete the Scenario Missions
After practicing in the terminal, move to Scenario Missions.
The lab contains four practical missions.
Each mission asks you to achieve a reconnaissance objective by executing the appropriate commands in the terminal.
Try solving the objective using what you learned in the Lab Guide rather than searching immediately for an answer.
Think about the information you need.
Do you need to discover ports?
Identify service versions?
Determine the operating system?
Perform deeper enumeration?
Use an NSE script?
Selecting the appropriate scan for the objective is an important part of learning Nmap.
Completing the missions also contributes to your overall lab progress.
Test Your Knowledge
After completing the terminal exercises and missions, open the Knowledge Check.
The assessment contains 10 questions covering concepts related to network scanning and vulnerability assessment.
Use the assessment as a way to identify gaps in your understanding rather than simply trying to achieve a perfect score.
If you miss a question about service detection, return to the terminal and compare a normal scan with -sV.
If OS fingerprinting is unclear, experiment again with -O.
If NSE concepts are difficult, review the script examples and observe how script output differs from normal port scanning.
This turns the assessment into another learning tool rather than just a final score.
A Practical Reconnaissance Workflow
When learning Nmap, it helps to develop a repeatable process.
A simplified workflow might look like this:
1. Identify the target
Know exactly which system or lab environment you are authorized to assess.
2. Discover reachable systems
Determine which hosts are available.
3. Identify open ports
Find network services that are exposed.
4. Detect services
Determine what software may be running behind those ports.
5. Gather additional information
Use operating-system detection or other appropriate reconnaissance techniques.
6. Perform targeted enumeration
Use NSE or more specific scans when additional information is required.
7. Analyze the attack surface
Determine which exposed services deserve further investigation.
The purpose of reconnaissance is not to run every possible scan.
The goal is to collect useful information systematically.
Offensive and Defensive Uses of Nmap
Nmap is often associated with penetration testing, but network scanning is also valuable to defenders.
Security teams can use authorized scanning to identify unexpected services, forgotten systems, unnecessary exposed ports, and configuration problems.
System administrators can use the same concepts to understand what their servers expose to the network.
The technology itself is therefore useful on both sides of cybersecurity.
The important factor is authorization.
Only scan networks and systems that you own or have explicit permission to assess.
Who Is This Lab For?
The CertInstructor Nmap Lab is useful for:
-
Cybersecurity students
-
Ethical hacking students
-
Penetration testing learners
-
SOC and blue-team learners
-
Network administrators
-
System administrators
-
Certification candidates
-
Anyone learning network reconnaissance
It can complement certification preparation where learners are expected to understand network discovery, port scanning, service enumeration, vulnerability assessment, or penetration-testing concepts.
Simulator First, Real Lab Next
The CertInstructor Nmap Lab is intentionally a simulation.
That makes it useful for learning syntax and developing a reconnaissance workflow without needing to build multiple virtual machines first.
Once you understand the concepts, the next step is to practice with the real Nmap utility inside your own authorized lab environment.
For example, you can build a small isolated environment using virtual machines and compare real Nmap output with what you learned in the simulator.
The simulator helps you understand what to do and why.
A real lab can then help you experience how scanning behaves on actual systems and networks.
Start Practicing
Network reconnaissance becomes much easier to understand once you stop treating Nmap commands as isolated syntax and start using them as part of a structured investigation.
Start with basic discovery.
Identify ports.
Enumerate services.
Collect more information when necessary.
Analyze what the results tell you about the target's exposed attack surface.
You can practice the complete workflow in your browser with the free CertInstructor Nmap Penetration Testing Lab:
https://go.certinstructor.org/labs/nmap/
No installation is required to begin.
Open the lab, launch the terminal, and start practicing.
CertInstructor — Learn · Practice · Certify
Explore more learning resources:
0 comentarios