Naabu
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- api, Linux, Mac, self-hosted, Windows

Summary
Naabu is a free, open-source command-line port scanner that finds valid ports on hosts. It uses SYN, CONNECT, and UDP scans and accepts hosts, IP addresses, CIDR ranges, and ASNs, supplied directly, from files, or through standard input. Results can be returned as JSON, CSV, text, or standard output. It supports IPv4 and experimental IPv6 scanning, DNS port scans, passive enumeration with Shodan InternetDB, and experimental host discovery. Naabu can integrate with Nmap for service discovery and version detection, and discovered ports can be passed to ProjectDiscovery's httpx to identify running HTTP servers. The CLI can upload or show scan output in the ProjectDiscovery Cloud dashboard. Installation options include ready-to-run binaries, Docker, and Go. Packet capture requires libpcap on Linux and macOS or Npcap on Windows. Service version detection also needs a local Nmap service probe database or a custom path. The README recommends running as root for best results and adjusting scan flags and rate on local systems.
Who it is for
Naabu is aimed at attack-surface discovery in bug-bounty work and penetration tests. It suits users who work with command-line scanning and related tools such as Nmap and httpx.
What is good
- Scans with SYN, CONNECT, and UDP probes.
- Accepts hosts, IPs, CIDRs, and ASNs.
- Supports JSON, CSV, text, and standard output.
- Can send discovered ports to ProjectDiscovery's httpx.
- Free and open source.
What to know first
- IPv6 scanning is marked experimental.
- Host discovery is marked experimental.
- Packet capture requires libpcap or Npcap.
- Version detection needs an Nmap probe database.
Everything Xiaomi review
Naabu: the full review
Naabu offers multiple scan types and input and output options for port discovery workflows. Be aware that some features are experimental and packet capture and version detection have additional requirements.
Overview
Naabu is a free, open-source command-line port scanner from ProjectDiscovery for finding valid ports across hosts and networks. It suits security practitioners who build attack-surface discovery workflows around other tools; its strength is flexible scanning and pipeline use, not a graphical interface.
SYN, CONNECT, and UDP scans cover different probing approaches, while target input and output options make Naabu adaptable to scripted work. It is a poor fit for readers who want a point-and-click scanner or a turnkey service inventory: IPv6 and host discovery are experimental, and deeper version detection depends on a separate Nmap probe database.
Key features
Scanning and target handling
Naabu accepts hosts, IPs, CIDRs, and ASNs, supplied directly, from a file, or through standard input. That breadth is useful when a target set comes from different stages of an assessment. It supports IPv4 and IPv6, but IPv6 and host discovery are marked experimental, so they are less dependable choices for workflows that require mature behavior.
Alongside active SYN, CONNECT, and UDP probing, passive port enumeration can use Shodan InternetDB. CDN/WAF exclusion can restrict scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula, and Sucuri IPs. This is a targeted safeguard for those networks, not a general substitute for setting a careful scan scope.
Results and integrations
Results can be emitted as JSON, CSV, text, or standard output, giving operators both structured exports and a natural command-line handoff. Discovered ports can be piped to ProjectDiscovery's httpx to identify running HTTP servers. Nmap integration supports service discovery and additional scans; Naabu can identify services by port and detect versions with Nmap service probes, but version detection requires the probe database from a local Nmap installation or a custom path.
The CLI can upload or display scan output in the ProjectDiscovery Cloud dashboard and associate results with team and asset IDs. It can be installed from ready-to-run binaries, Docker, or Go. Packet capture requires libpcap on Linux and macOS or Npcap on Windows; the README recommends root privileges for best results and tuning flags and scan rate on local systems. Those requirements make it more suitable for technically comfortable users than casual scanning.
Naabu is intended for authorized attack-surface discovery, including bug-bounty work and penetration tests. Its README places responsibility for use on the user and disclaims liability for misuse or damage; operators should keep scans within authorized scope.
Pricing
Naabu is free: the Open source plan costs 0.00 USD per free and provides an MIT-licensed port-scanning tool. It is a strong fit for individual practitioners and teams that can operate a CLI tool and supply any needed system dependencies themselves. The plan has API access and exports in JSON, CSV, TXT, and STDOUT; no paid Naabu tier is presented, so there is no higher plan to compare against.
Platforms
Naabu is available for Linux, macOS, and Windows, as well as API and self-hosted use. It is deployed as a CLI tool, with scanning scope listed as internet. The operating-system-specific packet-capture dependency remains important: libpcap is needed on Linux and macOS, and Npcap on Windows.
Who it's for
Choose Naabu if you need a free scanner that can take varied target inputs, produce machine-readable results, and feed a larger attack-surface workflow. Bug-bounty hunters and penetration testers who already use command-line tools are its clearest audience. Look elsewhere if you need a GUI-first product, mature experimental features, or version detection without installing or pointing Naabu to Nmap's probe database.
Pros and cons
- Pro: SYN, CONNECT, and UDP scans plus passive enumeration give operators several ways to discover ports.
- Pro: Hosts, IPs, CIDRs, ASNs, files, and standard input support varied target-supply workflows.
- Pro: JSON, CSV, text, and standard output suit both reporting and command-line pipelines.
- Con: IPv6 and host discovery are experimental, limiting their appeal for workflows that need established behavior.
- Con: Packet capture needs an additional platform-specific dependency, and best results may require root access and scan-rate tuning.
- Con: Version detection needs an external Nmap service-probe database rather than a bundled one.
Alternatives
Nmap is a free alternative for users who want a port scanner with a free end-user license; redistribution within commercial software or hardware products is not allowed by that license.
RustScan is another free, open-source port scanner to consider, including if Android support matters.
ScanSearch is worth considering for an internet-scanning service with a paid per-kpps plan, unlimited results per scan, full CSV/JSON export, and up to 10 queued scans.
Unicornscan is a free GPL option with downloadable packages and source.
Pentest-Tools Port Scanner offers web and API access, with a free tier for open-port and service discovery and a paid NetSec plan starting at 95.00 USD per month.
Nmap Online Scan is a web-based freemium alternative, with 10 scan credits priced at 1.99 USD once.
Masscan and NetsCLI are also free alternatives for Windows, macOS, and Linux.
Verdict
Naabu is a sound choice for security practitioners who want a free, scriptable port scanner that fits into attack-surface discovery pipelines. Its broad inputs, several scan types, and structured outputs are compelling for that audience; users who need experimental features to be dependable, graphical operation, or self-contained version detection should look elsewhere.
Naabu plans and pricing
All plansCompared on port scanner software
- Free plan
- Yesgithub.com
- Deployment
- cligithub.com
- Scan scope
- internetgithub.com
- Service detection
- Yesgithub.com
- API access
- Yesgithub.com
- Export formats
- JSON, CSV, TXT, STDOUTgithub.com
Facts
- Purpose
- Naabu is a Go port-scanning tool that enumerates valid ports on hosts using SYN, CONNECT, and UDP scans.github.com · 1 Oct 2026
- Scanning
- It supports fast SYN, CONNECT, and UDP probe-based scanning.github.com · 1 Oct 2026
- Inputs
- It accepts STDIN, hosts, IPs, CIDRs, and ASNs as scan inputs.github.com · 1 Oct 2026
- Outputs
- It supports JSON, TXT, and standard-output formats.github.com · 1 Oct 2026
- IPv4 and IPv6
- IPv4 and IPv6 port scanning is supported, with IPv6 marked experimental in the feature list.github.com · 1 Oct 2026
- Passive enumeration
- Passive port enumeration can use Shodan InternetDB.github.com · 1 Oct 2026
- Host discovery
- Host discovery scanning is available and marked experimental.github.com · 1 Oct 2026
- Nmap integration
- Naabu integrates with Nmap for service discovery and additional scans.github.com · 1 Oct 2026
- Cloud dashboard
- The CLI can upload or display scan output in the ProjectDiscovery Cloud dashboard and can associate results with team and asset IDs.github.com · 1 Oct 2026
- CDN and WAF exclusion
- CDN/WAF exclusion can limit scans to ports 80 and 443 for supported Cloudflare, Akamai, Incapsula, and Sucuri IPs.github.com · 1 Oct 2026
- Installation
- The maker provides ready-to-run binaries, Docker installation, and Go installation.github.com · 1 Oct 2026
- Platform prerequisites
- Packet capture requires libpcap on Linux and macOS or Npcap on Windows.github.com · 1 Oct 2026
- Operational requirement
- The README recommends running Naabu as root for best results and tuning flags and scan rate on local systems.github.com · 1 Oct 2026
- Pipeline integration
- Discovered ports can be piped to httpx to identify running HTTP servers.github.com · 1 Oct 2026
- Audience
- ProjectDiscovery describes Naabu as designed for attack-surface discovery in bug-bounty work and penetration tests.github.com · 1 Oct 2026
- Support
- ProjectDiscovery directs users to GitHub and Discord for help with its open-source tools.github.com · 1 Oct 2026
- Safety notice
- The Naabu README says users are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 1 Oct 2026
- Scan types
- It supports SYN, CONNECT and UDP scans.github.com · 2 Oct 2026
- Host inputs
- Inputs can include hosts, IPs, CIDRs and ASNs, supplied directly, from a file or through standard input.github.com · 2 Oct 2026
- Discovery
- Features include DNS port scanning, experimental host discovery, IPv4/IPv6 scanning and passive port enumeration using Shodan InternetDB.github.com · 2 Oct 2026
- Integrations
- It integrates with Nmap for service discovery and can pipe discovered ports to ProjectDiscovery's httpx tool.github.com · 2 Oct 2026
- Cloud integration
- CLI options can upload or view scan output in the ProjectDiscovery Cloud dashboard.github.com · 2 Oct 2026
- Output formats
- It supports JSON, CSV, text and standard output.github.com · 2 Oct 2026
- Installation requirement
- The installation instructions require libpcap for packet capture; they name Linux, macOS and Windows installation options.github.com · 2 Oct 2026
- Service probe limit
- Naabu does not include the Nmap service probe database, so service version detection requires that database from a local Nmap installation or a custom path.github.com · 2 Oct 2026
- Security notice
- The README warns users that they are responsible for their actions and that developers assume no liability for misuse or damage.github.com · 2 Oct 2026
- Intended users
- The README describes Naabu as designed to work with other tools for attack surface discovery in bug bounties and penetration tests.github.com · 2 Oct 2026
Best Naabu alternatives
See all 12Where it ranks on Everything Xiaomi
Is Naabu yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/projectdiscovery/naabu/blob/dev/README.· checked 1 Oct 2026
- github.com/projectdiscovery· checked 1 Oct 2026
- github.com/projectdiscovery/naabu· checked 2 Oct 2026

