Releases: Criseda/NetScanner
Releases · Criseda/NetScanner
Release list
v1.4.0
Port scans name the services they find:
- Named Open Ports: Every open port is named from an embedded table of about 6,000 TCP ports. The table combines the official IANA service registry with a curated overlay of friendly labels, categories and common unofficial uses (RDP instead of
ms-wbt-server, Home Assistant on 8123). The official IANA name is always reported alongside the label, and ports known only from common use have none. No network lookups, no flags. --jsonPort Fields: Port events gainservice,iana,descriptionandcategory, eachnullwhen unknown. Existing fields are unchanged, andsummary.open_portsis still a list of numbers. NetScannerDesktop shows these as columns in its Port scan table. See docs/README.md for the fields and categories.- Port Table: Text output streams
Open port: 3389 (RDP). The closingOpen ports: 22, 80line is replaced by an aligned PORT / SERVICE / IANA / DESCRIPTION table with a count and elapsed time, like-s.⚠️ Behavior change for scripts that scrape the text; use--json. - Generator Tooling:
scripts/generate_ports.pypacks the IANA registry andscripts/port_overlay.txtintosrc/core/data/ports.bin, and reports which ports changed since the last run.
$ ns -p 192.168.1.10 1-1024
Open port: 22 (SSH)
Open port: 80 (HTTP)
Open port: 445 (SMB)
PORT SERVICE IANA DESCRIPTION
22 SSH ssh The Secure Shell (SSH) Protocol
80 HTTP http World Wide Web HTTP
445 SMB microsoft-ds Windows file sharing (SMB over TCP)
3 open ports (1.2s)
$ ns -p 192.168.1.10 3389 --json
{"type":"port","port":3389,"service":"RDP","iana":"ms-wbt-server","description":"Remote Desktop Protocol (Windows)","category":"remote"}
{"type":"summary","open_ports":[3389],"elapsed_ms":4}
Assets Included
windows.zip: Windows x86_64 standalone executable (ns.exe)linux-x86_64.zip: Linux x86_64 standalone binary (ns)linux-arm64.zip: Linux ARM64 standalone binary (ns)macos-arm64.zip/macos-x86_64.zip: coming shortly. macOS binaries must be built and codesigned on a Mac; without the signature, macOS hides the ARP table.
SHA-256:
4636bfb26b6bff26f111bddc1dabb4e5377f8b2f08c475be6de3905688c97222 windows.zip
c0ebfc615e78694ca11089af7c7914165d740cb007e4eaa235a888d6babd8341 linux-x86_64.zip
2776e74e064f7d824f974c302883d8af835087ded190ea4dbdab091731eda378 linux-arm64.zip
Full changelog: v1.3.0...v1.4.0
v1.3.0
Machine-readable output for scripts and frontends, and reliable exit codes:
--jsonOutput: Add--jsonto-sor-pfor one JSON object per line (start,host,host_detail,port,summary,error). Scripts and frontends such as NetScannerDesktop no longer have to scrape the human-readable text. Hostnames and manufacturer names are JSON-escaped. See docs/README.md for the format.- Exit Codes: Invalid input now exits with status 1 (it used to exit 0), so scripts can tell a failure from a scan that found nothing. A malformed subnet now gives a clear message instead of a raw error trace.
⚠️ Behavior change for scripts that relied on exit 0. - Redirected Output Fixed:
ns -s ... > hosts.txtno longer garbles the file. Every line used to be written at the start of the file, overwriting the previous one. Pipes and terminals were not affected. - macOS Builds:
zig buildno longer prints "replacing existing signature" on every run.
$ ns -s 192.168.1.0/24 --resolve --json
{"type":"start","mode":"subnet","cidr":"192.168.1.0/24","first":"192.168.1.0","last":"192.168.1.255"}
{"type":"host","ip":"192.168.1.10","source":"tcp"}
{"type":"host_detail","ip":"192.168.1.10","hostname":"nas-storage","mac":"00:11:32:11:22:33","vendor":"Synology Incorporated"}
{"type":"summary","hosts":1,"elapsed_ms":1843}
Assets Included
windows.zip: Windows x86_64 standalone executable (ns.exe)linux-x86_64.zip: Linux x86_64 standalone binary (ns)linux-arm64.zip: Linux ARM64 standalone binary (ns)macos-arm64.zip/macos-x86_64.zip: coming shortly. macOS binaries must be built and codesigned on a Mac; without the signature, macOS hides the ARP table.
SHA-256:
ff857ac662742996a71471c74b3a4e6275dcda7dbc913239cef27a38b9f21e1b windows.zip
2db9fb6fd063aace60af10806dcf421f99b0c0866acf53bf6a850e444f4f4ac7 linux-x86_64.zip
7dbe16b19f505e5517b9c199e150010f6d43592050998f6e37840d290f4e0017 linux-arm64.zip
Full changelog: v1.2.2...v1.3.0
v1.2.2
Fixes missing MAC addresses and manufacturers on macOS (macOS 27 hid them):
- macOS ARP Table Fix: macOS 27 hides the kernel ARP table from third-party binaries, so
--vendor/--resolveshowed-for every MAC and manufacturer, and the ARP harvest silently missed quiet hosts.nsnow reads the table directly viasysctl, and the macOS binaries are ad-hoc codesigned with the identifierio.github.criseda.netscanner, which macOS requires before returning it. No privileges needed. In testing, a /23 scan went from 8 hosts with blank columns to 37 hosts with MACs and manufacturers. - Clear Warning: If the table still comes back empty,
nsnow explains why instead of leaving the columns blank. - Known Limitation: Run
nsdirectly from a shell. When another program launches it (includingzig build run), macOS still hides the table. - Release Builds: macOS binaries must be built on a Mac to be signed; see
docs/README.md.
Assets Included
windows.zip: Windows x86_64 standalone executable (ns.exe)macos-arm64.zip: macOS Apple Silicon standalone binary (ns)macos-x86_64.zip: macOS Intel standalone binary (ns)linux-x86_64.zip: Linux x86_64 standalone binary (ns)linux-arm64.zip: Linux ARM64 standalone binary (ns)
v1.2.1
Hardware manufacturer identification data upgrade and binary lookup engine:
- Full Wireshark OUI Database: Upgraded the embedded hardware manufacturer database from ~1,969 prefixes to the complete Wireshark / IEEE database (39,914 24-bit OUIs), resolving 100% of standard IEEE-assigned vendors worldwide (including all 1,553 Apple, 971 Samsung, 682 Intel, 1,252 Cisco, and 339 Espressif IoT prefixes previously omitted).
- Binary Lookup Table Architecture: Pre-packs sorted 8-byte records and a deduplicated string pool into
oui.bindirectly embedded in.rodata, eliminating compile-time text parsing bottlenecks while maintaining sub-microsecond binary search lookup (< 20ns per MAC) with zero memory allocations and zero startup delay. - Generator Tooling: Added
scripts/generate_oui.pyfor automated updates from upstream Wireshark automated data distributions. - Custom Database Support: Retains full runtime parsing and reload compatibility for
--oui-file <path>. - Privacy & Documentation Sanitization: Fully audited and sanitized all documentation examples and test fixtures to generic synthetic devices and IPs.
Assets Included
windows.zip: Windows x86_64 standalone executable (ns.exe)macos-arm64.zip: macOS Apple Silicon standalone binary (ns)macos-x86_64.zip: macOS Intel standalone binary (ns)linux-x86_64.zip: Linux x86_64 standalone binary (ns)linux-arm64.zip: Linux ARM64 standalone binary (ns)
v1.2.0
Hostname resolution and hardware manufacturer lookup for subnet scans (-s), with zero extra privileges or external tools required:
--resolve: Automatically resolves hostnames (via Reverse DNS PTR, RFC 6762 mDNS port 5353 queries, and RFC 1002 NetBIOS Name Service queries) and hardware manufacturers (via ARP table MAC extraction and embedded OUI lookup).--hostname: Resolves hostnames only (mDNS, NetBIOS NBNS, and Reverse DNS with domain suffix stripping).--vendor: Looks up MAC addresses and hardware manufacturer names only, with fallback to WindowsSendARPfor local interface / missing ARP entries.--oui-file <path>: Allows loading an external Wiresharkmanufor IEEE OUI database file for custom or offline OUI lookups, with support for colon (:) and hyphen (-) delimiters and varying hex widths.- Embedded OUI database: Bundles ~2,000 curated, balanced hardware manufacturer prefixes parsed at compile time from standard Wireshark flat format and sorted in
.rodatafor sub-microsecond binary search lookup (< 50ns per host) with zero external runtime dependencies. - Ping-blocking host discovery: ARP harvest pass verifies candidates that drop ICMP ping via a parallel SendARP worker pool on Windows and kernel neighbor reachability evaluation (REACHABLE/DELAY states) on Linux, capturing firewalled IoT devices and network gear (GL.iNet, TP-Link, smart home gear) in milliseconds without stalling discovery sweeps.
- Terminal escape sequence filtering: Enforces printable ASCII validation on hostnames retrieved over NetBIOS and mDNS to prevent ANSI escape sequence injection.
- Redesigned usage & help formatting: Clear, structured CLI overview with categorized sections (
COMMANDS,SUBNET OPTIONS,PORT OPTIONS,GLOBAL FLAGS, andEXAMPLES) and-h/-vshorthands. - Output formatting: Displays an aligned tabular view (
IP,HOSTNAME,MAC,MANUFACTURER) when resolution flags are used, while preserving the clean, compact numerical recap when flags are omitted. - Fully cross-platform across Windows, Linux, and macOS without requiring root or administrator privileges.
v1.1.0
Port scanning is faster and quieter, with no new privileges required:
- Fixed worker pools replace thread-per-port (and thread-per-IP in
discovery): a full 65k range needs hundreds of threads instead of
tens of thousands. A 200-port loopback scan drops from about 4.2s
to about 0.6s on Windows. - Port probes use a dedicated 500ms timeout while discovery keeps its
longer Windows bound, so slow RSTs still count as host-up.
Override it per scan withns -p <ip> <range> --timeout <ms>. - Results are sorted ascending; reversed ranges are rejected
(InvalidPortRange, the CLI still accepts either order); the
silent port-137 skip, the per-port sleep, per-port filtered stderr
lines, and a leftover TEMP timing print are gone. ipStringToBytesrejects empty octets and/0CIDRs no longer
overflow the mask computation.
v1.0.0
First stable release: reliable no-root LAN discovery plus port
scanning on macOS, Linux and Windows.
Discovery:
- The default TCP plus ARP engine sweeps a
/24in about 2 seconds,
down from 494 seconds with naive ping sweeping. The TCP sweep finds
hosts with open ports, and the ARP harvest pass catches quiet hosts
that answer ARP but drop TCP. Harvest only candidates get a targeted
probe before being reported, so stale table entries do not turn into
false positives. - The
--pingfallback uses one ICMP ping per host for networks where
TCP plus ARP does not fit. - Results stream as hosts are found, then a sorted recap lists every
host numerically with a one line summary of host count and elapsed
time.
Scanning:
- Port scans share the TCP connect timeout, so filtered ports report
quickly instead of stalling. - Commands are unified under
-sfor discovery and-pfor ports,
with--helpand--versionalongside.
Platforms and toolchain:
- Ported to Zig 0.16.0.
- The Windows discovery path works natively, with a Winsock connect
timeout, Windowsarp -aparsing, and calmer WSA startup and
cleanup. - Linux is validated in the Docker lab (see
docker/README.md),
including anip neighfallback whenarpis missing and per-OS
ping wait flags. developis merged intomain, which is now the only long lived
branch.- CI builds and runs the tests on Linux, macOS and Windows.
First Release
v0.3.0 Version v0.3.0