# Masscan

{% embed url="<https://github.com/robertdavidgraham/masscan>" %}
Asynchronous high-speed TCP port scanner
{% endembed %}

### Find open ports

The options masscan uses are very similar to nmap. It accepts a subnet or individual host as a target, and using the `-p` syntax you can provide a list, range or all ports using `-p-`. Then the output formats like `-oX` for XML or `-oJ` for JSON are useful when parsing the results with other tools afterwards.&#x20;

{% code title="Example" %}

```bash
sudo masscan 192.168.1.0/24 -p- --rate 100000 -oX out.xml
```

{% endcode %}

### Convert output to nmap format

Because masscan uses its own version of the XML output format, some tools won't work with this kind of output. To convert the masscan XML to nmap XML, we need to do two things:

1. Optionally: change the ownership from the output file from root to our current user
2. Remove the comment line `<!-- masscan v1.0 scan -->`

```bash
sudo chown $USER:$(id -gn) $1
sed -i '/<!-- masscan v1.0 scan -->/d' $1
```


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://book.jorianwoltjer.com/web/enumeration/masscan.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
