Information Gathering
Netdiscover is an active/passive ARP reconnaissance tool for discovering live hosts on a network. It sends ARP requests and listens for responses to identify devices, IP addresses, MAC addresses, and vendor information without performing port scans.
sudo apt install netdiscover
netdiscover [options] [target]
Netdiscover is a specialized ARP-based network reconnaissance tool for discovering live hosts on local networks. It operates at Layer 2 using ARP, making it faster and more reliable than IP-based discovery methods for local network host enumeration.
The tool supports two modes: active mode sends ARP requests to all IPs in a range and listens for responses, while passive mode silently listens for ARP traffic on the network without transmitting. Both modes reveal IP addresses, MAC addresses, and vendor information.
Security professionals use Netdiscover during initial network reconnaissance to map live hosts before deeper enumeration with Nmap or other scanning tools. Its passive mode is particularly valuable for stealthy assessments.
netdiscover -r 192.168.1.0/24Active scan — send ARP requests to discover all hosts on a subnetnetdiscover -pPassive mode — listen for ARP traffic without sending requestsnetdiscover -i eth0Specify interface — capture ARP packets on a specific network interfacenetdiscover -r 192.168.1.0/24 -fFast mode — reduce wait time between ARP requestsnetdiscover -l scan.txtRead targets — discover hosts from a file containing IP rangesnetdiscover -c 5Countdown — stop after discovering 5 hostsnetdiscover -r 192.168.1.0/24 -s 192.168.1.1Source IP — spoof source address in ARP requestsnetdiscover -r 192.168.1.0/24 -NNo header — suppress the display header for clean script parsingnetdiscover -P -r 192.168.1.0/24Print & exit — output results in a parsable format and quitnetdiscover -r 10.0.0.0/8 -f -s 2Wide sweep — fast scan a large range with 2ms inter-packet sleepnetdiscover -i wlan0 -pPassive Wi-Fi — silently harvest hosts on a wireless interfacenetdiscover -r 192.168.1.0/24 -m maclist.txtMAC filter — only report hosts matching MACs in a list filenetdiscover -S -r 192.168.1.0/24Sleep suppression — enable classic hardcoded sleep-time timingnetdiscover -L -r 192.168.1.0/24Continuous — keep scanning in a loop without stoppingIdentify all live hosts on a local network segment through ARP scanning.
Listen for ARP traffic without sending packets for stealthy host discovery.
Identify device types by MAC address vendor prefixes (Cisco, Dell, Apple, etc.).
Map network topology by discovering all active IP addresses and their MAC addresses.
Identify unauthorized devices connected to the network by unexpected MAC addresses.
Discover live hosts to create targeted lists for detailed Nmap scanning.
Information Gathering
Network scanner with ARP-based host discovery (-sn) plus deep port and service scanning.
Information Gathering
ARP scanner with MAC vendor database and fingerprinting capabilities.
Sniffing & Spoofing
Network attack and monitoring framework with ARP spoofing capabilities.
Sniffing & Spoofing
ARP spoofing tool for redirecting traffic on local networks.
Sniffing & Spoofing
Comprehensive MITM attack suite with ARP poisoning and protocol dissection.
Netdiscover displays a table with IP Address, MAC Address, Count (response count), Len (packet length), MAC Vendor / Hostname. Active mode sends ARP requests and displays responding hosts. Passive mode listens for ARP broadcasts from existing network traffic, revealing hosts without sending any packets.
This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.