Nmap
What it’s for
Port and service discovery: it maps what’s listening on a host or network. Usually the first thing a test runs.
Where it shines
- Reliable, everywhere, and scriptable via the NSE engine
- The de-facto standard, so results are well understood
Where it falls down
- Loud and easily logged
- Default timing can be slow, or fast enough to trip an IDS
My take
[EDIT ME: your one-line verdict — day-one essential, learn later, or overhyped, in your own words.]