TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer (2026)

Simulate RFC 9293 TCP state transitions and Nmap port scan packet exchanges (`-sS` Half-Open SYN, `-sT` Connect, `-sF` FIN, `-sX` Xmas, `-sN` Null, `-sA` ACK Firewall Probe, `-sU` UDP): inspect 8-bit TCP control flags and IDS/Snort detection rules.

TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer — Interactive Console
Runs locally in your browser • Instant output
6-Bit TCP Header Control Flags (0x02)Nmap Verdict: open
URG
0
ACK
0
PSH
0
RST
0
SYN
1
FIN
0
Packet Sequence Exchange Diagram
ATTACKER (Nmap)TARGET PORT 443SYN (Seq=0, Flags=0x02)SYN + ACK (Seq=0, Ack=1, Flags=0x12)RST (Tears down before full accept(), Flags=0x04)

Target listening socket replied SYN/ACK; scanner immediately sends RST to avoid completing 3-way handshake.

Snort / Suricata IDS Detection Signature
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"SCAN Nmap TCP SYN Scan"; flags:S; threshold:type both, track by_src, count 20, seconds 5; sid:1000401;)
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/tcp-flag-port-scan-handshake-visualizer/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/tcp-flag-port-scan-handshake-visualizer/">TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer — ZerosUniverse</a>

2026 RFC 9293 TCP Control Flags, Hex Bitmasks & Nmap Port State Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (tcp handshake stealth port scan visualizer)Updated 2026 Standard

The 8-bit TCP control flag byte (`CWR=0x80`, `ECE=0x40`, `URG=0x20`, `ACK=0x10`, `PSH=0x08`, `RST=0x04`, `SYN=0x02`, `FIN=0x01`) governs connection state transitions and port scan responses: an open port replies `SYN+ACK (0x12)` to a `SYN (0x02)` probe, a closed port replies `RST+ACK (0x14)`, and a stateful firewall drops the packet silently.

Flag Byte Formula: CWR(128) + ECE(64) + URG(32) + ACK(16) + PSH(8) + RST(4) + SYN(2) + FIN(1) | SYN+ACK = 2 + 16 = 18 (0x12)
SYN Packet Byte: tcp[13] == 0x02 (Decimal 2)
SYN-ACK Packet Byte: tcp[13] == 0x12 (Decimal 18)
Xmas Scan Byte (FIN+PSH+URG): tcp[13] == 0x29 (Decimal 41)
TCP Flag / Scan ProbeHex & Decimal BitmaskOpen Port Target ResponseClosed vs Filtered Firewall Response
SYN (3-Way Handshake / -sS)0x02 (Decimal 2 | tcp-syn)SYN+ACK (0x12) → Scanner sends RST (0x04)Closed: RST+ACK (0x14) | Filtered: No Response
SYN + ACK (Server Handshake Step 2)0x12 (Decimal 18 | SYN=2 + ACK=16)Client replies ACK (0x10) → ESTABLISHEDUnsolicited SYN+ACK triggers immediate RST (0x04)
PSH + ACK (Interactive Data Push)0x18 (Decimal 24 | PSH=8 + ACK=16)Flushes socket buffer to application immediatelyStandard HTTP/SSH payload transfer state
FIN / NULL / Xmas Scan (-sF/-sN/-sX)FIN: 0x01 | NULL: 0x00 | Xmas: 0x29Open Port: No Response (RFC 9293 drop)Closed Port: Replies RST+ACK (0x14) on POSIX
ACK Firewall Rule Probe (-sA)0x10 (Decimal 16 | tcp-ack)Unfiltered (Open or Closed): Replies RST (0x04)Stateful Firewall (Filtered): Silent Drop / ICMP
FIN + ACK vs RST + ACK TeardownFIN+ACK: 0x11 (17) | RST+ACK: 0x14 (20)0x11 initiates graceful 4-way close (TIME_WAIT)0x14 aborts connection immediately (port closed/IPS)
In-Depth ZerosUniverse Tutorial

What is Port Scanning and Types of Port Scans

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer

01

Select Scan Technique (TCP 3-Way, SYN `-sS`, FIN `-sF`, Xmas `-sX`, Null `-sN`, or ACK `-sA`)

Choose any scan technique from the top selector and set the simulated target port state (`Open`, `Closed`, `Filtered (Drop)`, or `Filtered (ICMP Reject)`).

02

Inspect the Packet Ladder Diagram & Sequence/Ack Numbers

Follow the animated packet arrows showing flags (`SEQ=1000, CTL=SYN`), target kernel RFC 9293 processing, and final Nmap port state classification.

03

Toggle the Interactive 8-Bit TCP Flag Bitmask Register

Click any of the 8 TCP control bits (`CWR` through `FIN`) to inspect the resulting hex value, RFC validity check, and matching `tcpdump` / Wireshark display filter.

04

Copy the Nmap Command & Corresponding Suricata Detection Rule

Grab the generated Nmap command for red-team testing alongside the Blue-Team Suricata signature that detects the probe.

Key Capabilities & Technical Architecture

Interactive Packet Sequence Ladder Diagram (Scanner ↔ Firewall ↔ Target)

Step through packet-by-packet exchanges (`SYN -> SYN/ACK -> RST` vs `FIN/PSH/URG -> RST/ACK`) across Open, Closed, Stateful Firewall, and Stateless ACL port states.

8-Bit TCP Header Flag Register & Hex Byte Calculator

Toggle individual TCP control bits (`CWR`, `ECE`, `URG`, `ACK`, `PSH`, `RST`, `SYN`, `FIN`) to compute the exact 8-bit binary mask, hexadecimal byte (`0x02`, `0x12`, `0x29`), and tcpdump filter expression (`tcp[13] == 0x29`).

Nmap CLI Command & Timing Template (`-T0` to `-T5`) Builder

Generate copy-ready Nmap commands combining scan technique flags, port ranges, decoy IPs (`-D`), packet fragmentation (`-f`), and IDS evasion timing controls.

Suricata / Snort IDS Signature & OS RFC 9293 Quirk Reference

See the exact Suricata/Snort alert rule that catches each scan type and understand why Windows/Cisco stacks violate RFC 9293 on FIN/Xmas/Null probes by sending `RST` on open ports.

Practical Use Cases

Mastering Nmap Port State Inference (Open vs Closed vs Open|Filtered)

Understand why a SYN scan positively identifies `open` via `SYN/ACK`, whereas a FIN, Null, or Xmas scan can only infer `open|filtered` when no `RST` packet comes back.

Distinguishing Stateful vs Stateless Firewalls with ACK (`-sA`) Scans

Simulate how an unsolicited `ACK` probe elicits an unfiltered `RST` from a stateless ACL router but gets silently dropped (or triggers ICMP Type 3 Code 13) on a stateful firewall.

Writing Custom `tcpdump` / Wireshark Bitmask Filters for SOC Hunting

Calculate exact byte-offset 13 bitmasks (such as `tcp[13] & 0x29 == 0x29` for Xmas scans or `tcp[13] == 0x00` for Null scans) to isolate port reconnaissance in PCAPs.

Frequently Asked Questions (FAQs)

Why is a TCP SYN scan (`nmap -sS`) called a 'Half-Open' stealth scan?+

In a full TCP 3-way handshake (`-sT`), the OS kernel sends `SYN`, receives `SYN/ACK`, and completes the connection with `ACK`, which causes `accept()` to return and writes an entry in application-layer logs. In a SYN scan (`-sS`), Nmap crafts raw packets and immediately sends a `RST` (Reset) as soon as `SYN/ACK` arrives, tearing down the embryonic connection before the application layer ever sees it—though modern stateful firewalls and EDRs still log it.

How do FIN (`-sF`), Null (`-sN`), and Xmas (`-sX`) scans detect open ports without sending SYN?+

According to RFC 9293 (formerly RFC 793) Section 3.10.7.4, if a packet arrives without the `SYN`, `RST`, or `ACK` bits set, a **closed** port must respond with a `RST` packet, whereas an **open** port must silently ignore and drop the out-of-state segment. By sending zero flags (Null), just `FIN`, or `FIN+PSH+URG` (lit up like a Christmas tree), the scanner identifies closed ports that reply with `RST` and marks silent ports as `open|filtered`.

Why do FIN, Xmas, and Null scans fail against Windows and Cisco targets?+

Microsoft Windows, Cisco IOS, and several BSD variants do not strictly follow RFC 9293's silent-drop rule for malformed flag combinations—their TCP stacks reply with `RST` to FIN, Null, and Xmas probes whether the port is open or closed, making every port appear `closed` to Nmap.

What does an Nmap ACK scan (`-sA`) actually discover?+

An ACK scan never determines whether a port is `open` or `closed`, because both open and closed ports on an unfiltered host reply to an unsolicited `ACK` with a `RST` packet. Instead, `-sA` maps firewall rulesets: ports that return `RST` are `unfiltered` (allowed through the firewall), while ports that return nothing or ICMP Type 3 Code 13 are `filtered` by a stateful inspection firewall.

How is `tcp[13] == 0x29` derived for detecting an Xmas scan in tcpdump?+

Byte offset 13 of the TCP header holds the 8 control flags: `CWR(128) ECE(64) URG(32) ACK(16) PSH(8) RST(4) SYN(2) FIN(1)`. An Nmap Xmas scan sets `FIN (1) + PSH (8) + URG (32) = 41` in decimal, which equals `0x29` in hexadecimal (`00101001` in binary).