Expand description
A best guess at a host’s operating system, from clues a scan already has, each named with where it came from.
This is not nmap’s -O. That sends deliberately malformed packets and
fingerprints how the TCP/IP stack answers, which needs raw sockets (so
administrator rights, and Npcap on Windows) and a fingerprint database
under nmap’s own licence. The clues here need neither:
- SMB: a Windows host’s NTLM challenge states its exact version and
build before any login (
os_hint/smb.rs); - SSH banner: OpenSSH usually names the distribution
(
OpenSSH_9.6p1 Ubuntu-3ubuntu13) or saysfor_Windows; - HTTP
Serverheader:Apache/2.4.58 (Ubuntu),Microsoft-IIS/10.0; - open ports: 135 with 445 is Windows’ RPC and file sharing;
- MAC vendor: an Apple or Raspberry Pi network card;
- ping TTL: hosts start the TTL at 64 (Linux, macOS, most Unix), 128 (Windows) or 255 (network gear), and a LAN hop barely lowers it.
The strongest clue sets the family; every clue is kept as evidence, so a reader can see both what was concluded and why, including clues that disagree. It’s a hint: a host can run anything behind any of these.
Structs§
- OsHint
- A best guess at a host’s operating system, and the clues behind it.