Naabu

Windows · Mac · Linux · Self-hosted · API

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely3 of 6 device platforms
  • DocumentedPlans, terms and facts published

Naabu is a command-line port-scanning tool for finding valid ports on hosts. It supports SYN, CONNECT and UDP scans, with inputs supplied as hosts, IP addresses, CIDR ranges or ASNs, either directly, from a file or through standard input. Results can be written as JSON, CSV, TXT or standard output. The tool supports IPv4 scanning; IPv6 and host discovery are marked experimental. Other discovery options include DNS port scanning and passive enumeration using Shodan InternetDB. Naabu can work with Nmap for service discovery and version detection, and discovered ports can be passed to ProjectDiscovery’s httpx to identify running HTTP servers. Its CLI can upload or display results in the ProjectDiscovery Cloud dashboard. Naabu is free, with ready-to-run binaries, Docker and Go installation options. Packet capture requires libpcap on Linux and macOS or Npcap on Windows. Service version detection needs a local Nmap service probe database or a custom path. The README recommends root privileges for best results and tuning flags and scan rate on local systems.

Who it is for

Naabu suits security practitioners doing attack-surface discovery for bug-bounty work or penetration tests. It is designed to work with other tools in a scanning workflow.

What is good

  • Free, MIT-licensed port-scanning tool.
  • Accepts hosts, IPs, CIDRs and ASNs.
  • Supports SYN, CONNECT and UDP scans.
  • Exports JSON, CSV, TXT and standard output.
  • Integrates with Nmap and ProjectDiscovery’s httpx.

What to know first

  • IPv6 and host discovery are experimental.
  • Packet capture requires a platform-specific dependency.
  • Service version detection needs an Nmap probe database.
  • README recommends root privileges for best results.

Freedom251 review

Naabu: the full review

Naabu brings several scan types, flexible inputs and output formats into a CLI workflow. Note the experimental features, packet-capture dependencies and service-probe requirement before planning scans.

Overview

Naabu is ProjectDiscovery’s command-line port scanner for security practitioners mapping exposed services across hosts and networks. It suits bug-bounty and penetration-testing workflows built around other tools; its range of scan methods and flexible target inputs are useful, but it is not a graphical scanner and some capabilities depend on experimental features or external components.

Users can provide hosts, IPs, CIDRs or ASNs directly, from a file or through standard input, then save results or pipe them into another tool. Use it only for systems you are authorized to scan: Naabu places responsibility for use on the user and disclaims liability for misuse or damage.

Key features

Scan methods and target coverage

SYN, CONNECT and UDP probes, along with DNS port scanning, give operators several ways to enumerate ports. IPv4 is supported; IPv6 and host discovery are marked experimental, so workflows that depend on either should account for that status. Passive enumeration through Shodan InternetDB offers another route to port information, distinct from active probing.

Service discovery and workflow links

Naabu integrates with Nmap for service discovery and additional scans, and can identify services by port. Version detection uses Nmap service probes, but Naabu does not bundle the probe database: users need a local Nmap installation or a custom database path. Discovered ports can be piped to ProjectDiscovery’s httpx to identify running HTTP servers, making Naabu a practical first stage in a command-line pipeline rather than a complete analysis environment.

Outputs, cloud and installation

Results can be emitted as JSON, CSV, text or standard output, which makes both saved reports and downstream processing possible. CLI options also upload or display results in the ProjectDiscovery Cloud dashboard and associate them with team and asset IDs. Ready-to-run binaries, Docker and Go installation are offered. Packet capture requires libpcap on Linux and macOS or Npcap on Windows; the README recommends root privileges for best results and tuning scan flags and rates on local systems.

For supported Cloudflare, Akamai, Incapsula and Sucuri IPs, CDN/WAF exclusion can restrict scans to ports 80 and 443. That is a focused safeguard, not a general substitute for choosing authorized targets and appropriate scan scope.

Pricing

Open source — 0.00 USD per free. The free, MIT-licensed plan provides Naabu as a port-scanning CLI, with internet scan scope, API access and JSON, CSV, TXT and STDOUT exports. There are no paid tiers or seat and quota terms to weigh in the stated plan. The trade-off is operational: packet capture has platform dependencies, best results may require root access, and service-version detection requires an external Nmap probe database.

Platforms

Naabu is listed for API, Linux, macOS, self-hosted and Windows use, with CLI as its deployment format. Packet-capture setup differs by operating system: libpcap is required on Linux and macOS, while Windows uses Npcap.

Who it's for

Naabu is best suited to security professionals and technically comfortable operators who need port enumeration as part of attack-surface discovery, bug bounty work or penetration tests. Its input and output options favor automation and integration. Readers looking for a graphical interface, or a self-contained service-version scanner without an Nmap probe database, should choose another approach.

Pros and cons

  • Pros: SYN, CONNECT, UDP and DNS scanning support varied port-enumeration workflows.
  • Pros: Hosts, IPs, CIDRs, ASNs and standard input accommodate both one-off targets and scripted pipelines.
  • Pros: JSON, CSV, text and standard output, plus Nmap, httpx and ProjectDiscovery Cloud integration, make results usable in broader workflows.
  • Cons: IPv6 scanning and host discovery are experimental, making them less suitable as assumed foundations for a production process.
  • Cons: Packet capture requires libpcap or Npcap, and the README recommends root privileges for best results.
  • Cons: Service-version detection requires a separate Nmap probe database, adding setup for users who need version details.

Alternatives

RustScan is another free port scanner for Linux, macOS, Windows, Android and self-hosted use; choose it if that platform range better fits your environment. Angry IP Scanner is free and open-source under GPLv2 for Linux, macOS and Windows, a fitting alternative for users seeking a scanner on those desktop platforms. Nmap is a free option for Linux, macOS and self-hosted use, with end-user use permitted under its license; choose it when you want the service-scanning tool Naabu integrates with directly.

ScanSearch offers an Internet Scanner paid plan at 0.30 USD per month, billed per kpps/month, with 100–10,000 kpps, unlimited results per scan, full CSV/JSON export and a queue of up to 10 scans; consider it when those stated scan quotas and exports suit your needs. Unicornscan is free GPL software with downloadable packages and source. Pentest-Tools Port Scanner has a free tier covering open-port and service discovery, as well as a NetSec plan starting at 95.00 USD per month; choose it if a web-based scanner is preferable. Nmap Online Scan offers 10 scan credits for a one-time 1.99 USD; it is a web-based alternative. Masscan is a free option for Windows, macOS and Linux.

Browse more options in Port Scanner Software.

Verdict

Choose Naabu if you need a free, flexible CLI port scanner that can feed results into an attack-surface discovery pipeline. Its scan methods, broad target inputs and export options are compelling for that role. Look elsewhere if you need a graphical workflow, experimental features to be dependable, or service-version detection without managing an Nmap probe database.

Naabu plans and pricing

All plans
Open source Free MIT-licensed port scanning tool github.com · 2 Oct 2026

Compared on port scanner software

Free plan
Yes
Deployment
cli
Scan scope
internet
Service detection
Yes
API access
Yes
Export formats
JSON, CSV, TXT, STDOUT

Best Naabu alternatives

See all 20