GO KALI FREE

Netdiscover

Information Gathering

Beginnerlow risk

Netdiscover is an active/passive ARP reconnaissance tool for discovering live hosts on a network. It sends ARP requests and listens for responses to identify devices, IP addresses, MAC addresses, and vendor information without performing port scans.

Installation

sudo apt install netdiscover

Basic Syntax

netdiscover [options] [target]

Quick Facts

Full Name
Netdiscover
License
GPL v2
Written In
C
Platforms
Linux
Category
Network Reconnaissance
Modes
Active ARP scan, Passive ARP listen
First Release
2009
Author
Alberto Gonzalez

Tool Overview

Netdiscover is a specialized ARP-based network reconnaissance tool for discovering live hosts on local networks. It operates at Layer 2 using ARP, making it faster and more reliable than IP-based discovery methods for local network host enumeration.

The tool supports two modes: active mode sends ARP requests to all IPs in a range and listens for responses, while passive mode silently listens for ARP traffic on the network without transmitting. Both modes reveal IP addresses, MAC addresses, and vendor information.

Security professionals use Netdiscover during initial network reconnaissance to map live hosts before deeper enumeration with Nmap or other scanning tools. Its passive mode is particularly valuable for stealthy assessments.

Common Commands

netdiscover -r 192.168.1.0/24Active scan — send ARP requests to discover all hosts on a subnet
netdiscover -pPassive mode — listen for ARP traffic without sending requests
netdiscover -i eth0Specify interface — capture ARP packets on a specific network interface
netdiscover -r 192.168.1.0/24 -fFast mode — reduce wait time between ARP requests
netdiscover -l scan.txtRead targets — discover hosts from a file containing IP ranges
netdiscover -c 5Countdown — stop after discovering 5 hosts
netdiscover -r 192.168.1.0/24 -s 192.168.1.1Source IP — spoof source address in ARP requests
netdiscover -r 192.168.1.0/24 -NNo header — suppress the display header for clean script parsing
netdiscover -P -r 192.168.1.0/24Print & exit — output results in a parsable format and quit
netdiscover -r 10.0.0.0/8 -f -s 2Wide sweep — fast scan a large range with 2ms inter-packet sleep
netdiscover -i wlan0 -pPassive Wi-Fi — silently harvest hosts on a wireless interface
netdiscover -r 192.168.1.0/24 -m maclist.txtMAC filter — only report hosts matching MACs in a list file
netdiscover -S -r 192.168.1.0/24Sleep suppression — enable classic hardcoded sleep-time timing
netdiscover -L -r 192.168.1.0/24Continuous — keep scanning in a loop without stopping

Step-by-Step Guide

  1. 1Identify the network interface connected to the target network: ip addr show
  2. 2Run an active scan on the target subnet: netdiscover -r <subnet>
  3. 3Review discovered hosts showing IP, MAC address, and vendor information
  4. 4Use passive mode on monitored networks to avoid generating ARP traffic
  5. 5Filter results by vendor to identify specific device types (routers, IoT, servers)
  6. 6Use discovered IPs as targets for deeper enumeration with Nmap or Enum4Linux
  7. 7Document the network layout including all discovered hosts and their manufacturers

Warnings

Use Cases

Host Discovery

Identify all live hosts on a local network segment through ARP scanning.

Passive Reconnaissance

Listen for ARP traffic without sending packets for stealthy host discovery.

Device Identification

Identify device types by MAC address vendor prefixes (Cisco, Dell, Apple, etc.).

Network Mapping

Map network topology by discovering all active IP addresses and their MAC addresses.

Rogue Device Detection

Identify unauthorized devices connected to the network by unexpected MAC addresses.

Pre-Nmap Reconnaissance

Discover live hosts to create targeted lists for detailed Nmap scanning.

Related Tools

Nmap

Information Gathering

Network scanner with ARP-based host discovery (-sn) plus deep port and service scanning.

arp-scan

Information Gathering

ARP scanner with MAC vendor database and fingerprinting capabilities.

Bettercap

Sniffing & Spoofing

Network attack and monitoring framework with ARP spoofing capabilities.

arpspoof

Sniffing & Spoofing

ARP spoofing tool for redirecting traffic on local networks.

Ettercap

Sniffing & Spoofing

Comprehensive MITM attack suite with ARP poisoning and protocol dissection.

Frequently Asked Questions

What is Netdiscover used for?

Netdiscover is an ARP-based network reconnaissance tool that discovers live hosts on a local network. It sends ARP requests (active) or listens for ARP traffic (passive) to identify devices by IP, MAC address, and vendor.

How is Netdiscover different from Nmap?

Netdiscover uses ARP at Layer 2 for host discovery within local networks, which is faster and more reliable than Nmap's IP-based scanning. Nmap provides deeper service and OS information after hosts are discovered.

Can Netdiscover run passively?

Yes, Netdiscover has a passive mode (-p) that listens for ARP traffic without sending any packets. This is useful for stealthy reconnaissance where you cannot risk detection.

What information does Netdiscover show?

Netdiscover displays IP addresses, MAC addresses, MAC vendor names, packet counts, and response timing for each discovered host.

How does ARP scanning work in Netdiscover?

ARP scanning works by broadcasting ARP requests to all possible IP addresses in a target range. Live hosts respond with their MAC addresses, allowing Netdiscover to build a table of IP-to-MAC mappings that identify all active devices on the local network segment.

Can Netdiscover detect rogue devices?

Yes, Netdiscover can detect rogue devices by comparing discovered MAC addresses against known device inventories. Unexpected MAC addresses from unfamiliar vendors indicate unauthorized devices that may need investigation for security compliance.

What is passive ARP detection?

Passive ARP detection (-p mode) listens for ARP traffic already present on the network without sending any packets. It captures ARP requests and replies from other devices, building a host list completely stealthily without generating any network noise.

How does active probing differ from passive detection?

Active probing sends ARP requests to all IPs in a range and waits for responses, which is faster but generates detectable traffic. Passive detection only listens for existing ARP traffic, which is stealthy but only discovers hosts that are actively communicating.

Can Netdiscover identify device vendors?

Yes, Netdiscover resolves MAC address prefixes to vendor names using the OUI (Organizationally Unique Identifier) database. This helps identify device types such as routers (Cisco), computers (Dell, HP), and mobile devices (Apple) on the network.

How is Netdiscover used for network mapping?

Netdiscover maps network topology by discovering all live hosts through ARP scanning. It reveals IP addresses, MAC addresses, and vendor information, creating a comprehensive inventory of devices that can be used as input for deeper enumeration with Nmap or other tools.

How do I limit the number of hosts Netdiscover finds?

Use the -c flag: netdiscover -r 192.168.1.0/24 -c 20 stops after discovering 20 hosts. This is useful for quick scans where you don't need a complete inventory of all devices.

Can Netdiscover scan specific port ranges?

No, Netdiscover operates at Layer 2 using ARP, which works at the network layer independent of ports. For port-specific scanning, use Nmap on hosts discovered by Netdiscover.

How do I use Netdiscover in continuous mode?

Use the -c flag without a count for continuous scanning: netdiscover -r 192.168.1.0/24 -c 0. Netdiscover continuously monitors for new hosts appearing on the network, useful for detecting intermittent devices.

Can Netdiscover detect ARP spoofing attacks?

Netdiscover shows current ARP mappings but is not specifically designed for ARP spoofing detection. For ARP anomaly detection, use arpwatch, XARP, or network IDS solutions that monitor for ARP table changes.

How do I use Netdiscover with specific network interfaces?

Use the -i flag: netdiscover -i eth0 -r 192.168.1.0/24. This specifies the network interface for scanning, useful on systems with multiple network adapters or when targeting specific network segments.

Can Netdiscover identify router and gateway devices?

Yes, Netdiscover identifies devices by MAC vendor prefix. Router manufacturers (Cisco, TP-Link, Netgear) are shown in the vendor field. Gateway devices are typically at .1 or .254 IP addresses.

How do I save Netdiscover results to a file?

Use the -P flag to save results in pcap format for Wireshark analysis: netdiscover -r 192.168.1.0/24 -P capture.pcap. For text output, redirect stdout: netdiscover -r 192.168.1.0/24 > hosts.txt.

Can Netdiscover work on virtual networks?

Netdiscover works on virtual networks (VMware, VirtualBox, Hyper-V) when the VM adapter is in bridged mode. Host-only or NAT mode limits ARP visibility to the virtual network only.

How do I use Netdiscover for compliance auditing?

Run periodic Netdiscover scans and compare results against your device inventory. Unexpected MAC addresses indicate unauthorized devices. Document findings for compliance reports showing network device inventory changes.

Tags

#reconnaissance#arp-scan#host-discovery#network-mapping#passive-recon

Output Explanation

Netdiscover displays a table with IP Address, MAC Address, Count (response count), Len (packet length), MAC Vendor / Hostname. Active mode sends ARP requests and displays responding hosts. Passive mode listens for ARP broadcasts from existing network traffic, revealing hosts without sending any packets.

Ethical Usage Notice

This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.