Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/tcp-flag-port-scan-handshake-visualizer/">TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer — ZerosUniverse</a>
2026 RFC 9293 TCP Control Flags, Hex Bitmasks & Nmap Port State Table
2026 Verified Reference
Quick Answer & 2026 Technical Summary (tcp handshake stealth port scan visualizer)Updated 2026 Standard
The 8-bit TCP control flag byte (`CWR=0x80`, `ECE=0x40`, `URG=0x20`, `ACK=0x10`, `PSH=0x08`, `RST=0x04`, `SYN=0x02`, `FIN=0x01`) governs connection state transitions and port scan responses: an open port replies `SYN+ACK (0x12)` to a `SYN (0x02)` probe, a closed port replies `RST+ACK (0x14)`, and a stateful firewall drops the packet silently.
How to Use TCP 3-Way Handshake & Stealth Port Scan (SYN/FIN/Xmas/Null/ACK) Visualizer
01
Select Scan Technique (TCP 3-Way, SYN `-sS`, FIN `-sF`, Xmas `-sX`, Null `-sN`, or ACK `-sA`)
Choose any scan technique from the top selector and set the simulated target port state (`Open`, `Closed`, `Filtered (Drop)`, or `Filtered (ICMP Reject)`).
02
Inspect the Packet Ladder Diagram & Sequence/Ack Numbers
Follow the animated packet arrows showing flags (`SEQ=1000, CTL=SYN`), target kernel RFC 9293 processing, and final Nmap port state classification.
03
Toggle the Interactive 8-Bit TCP Flag Bitmask Register
Click any of the 8 TCP control bits (`CWR` through `FIN`) to inspect the resulting hex value, RFC validity check, and matching `tcpdump` / Wireshark display filter.
04
Copy the Nmap Command & Corresponding Suricata Detection Rule
Grab the generated Nmap command for red-team testing alongside the Blue-Team Suricata signature that detects the probe.
Step through packet-by-packet exchanges (`SYN -> SYN/ACK -> RST` vs `FIN/PSH/URG -> RST/ACK`) across Open, Closed, Stateful Firewall, and Stateless ACL port states.
8-Bit TCP Header Flag Register & Hex Byte Calculator
Toggle individual TCP control bits (`CWR`, `ECE`, `URG`, `ACK`, `PSH`, `RST`, `SYN`, `FIN`) to compute the exact 8-bit binary mask, hexadecimal byte (`0x02`, `0x12`, `0x29`), and tcpdump filter expression (`tcp[13] == 0x29`).
Nmap CLI Command & Timing Template (`-T0` to `-T5`) Builder
See the exact Suricata/Snort alert rule that catches each scan type and understand why Windows/Cisco stacks violate RFC 9293 on FIN/Xmas/Null probes by sending `RST` on open ports.
Practical Use Cases
Mastering Nmap Port State Inference (Open vs Closed vs Open|Filtered)
Understand why a SYN scan positively identifies `open` via `SYN/ACK`, whereas a FIN, Null, or Xmas scan can only infer `open|filtered` when no `RST` packet comes back.
Distinguishing Stateful vs Stateless Firewalls with ACK (`-sA`) Scans
Simulate how an unsolicited `ACK` probe elicits an unfiltered `RST` from a stateless ACL router but gets silently dropped (or triggers ICMP Type 3 Code 13) on a stateful firewall.
Writing Custom `tcpdump` / Wireshark Bitmask Filters for SOC Hunting
Calculate exact byte-offset 13 bitmasks (such as `tcp[13] & 0x29 == 0x29` for Xmas scans or `tcp[13] == 0x00` for Null scans) to isolate port reconnaissance in PCAPs.
Frequently Asked Questions (FAQs)
Why is a TCP SYN scan (`nmap -sS`) called a 'Half-Open' stealth scan?+
In a full TCP 3-way handshake (`-sT`), the OS kernel sends `SYN`, receives `SYN/ACK`, and completes the connection with `ACK`, which causes `accept()` to return and writes an entry in application-layer logs. In a SYN scan (`-sS`), Nmap crafts raw packets and immediately sends a `RST` (Reset) as soon as `SYN/ACK` arrives, tearing down the embryonic connection before the application layer ever sees it—though modern stateful firewalls and EDRs still log it.
How do FIN (`-sF`), Null (`-sN`), and Xmas (`-sX`) scans detect open ports without sending SYN?+
According to RFC 9293 (formerly RFC 793) Section 3.10.7.4, if a packet arrives without the `SYN`, `RST`, or `ACK` bits set, a **closed** port must respond with a `RST` packet, whereas an **open** port must silently ignore and drop the out-of-state segment. By sending zero flags (Null), just `FIN`, or `FIN+PSH+URG` (lit up like a Christmas tree), the scanner identifies closed ports that reply with `RST` and marks silent ports as `open|filtered`.
Why do FIN, Xmas, and Null scans fail against Windows and Cisco targets?+
Microsoft Windows, Cisco IOS, and several BSD variants do not strictly follow RFC 9293's silent-drop rule for malformed flag combinations—their TCP stacks reply with `RST` to FIN, Null, and Xmas probes whether the port is open or closed, making every port appear `closed` to Nmap.
What does an Nmap ACK scan (`-sA`) actually discover?+
An ACK scan never determines whether a port is `open` or `closed`, because both open and closed ports on an unfiltered host reply to an unsolicited `ACK` with a `RST` packet. Instead, `-sA` maps firewall rulesets: ports that return `RST` are `unfiltered` (allowed through the firewall), while ports that return nothing or ICMP Type 3 Code 13 are `filtered` by a stateful inspection firewall.
How is `tcp[13] == 0x29` derived for detecting an Xmas scan in tcpdump?+
Byte offset 13 of the TCP header holds the 8 control flags: `CWR(128) ECE(64) URG(32) ACK(16) PSH(8) RST(4) SYN(2) FIN(1)`. An Nmap Xmas scan sets `FIN (1) + PSH (8) + URG (32) = 41` in decimal, which equals `0x29` in hexadecimal (`00101001` in binary).