A concurrent TCP port scanner and continuous network monitor built in Go. Scans a range of IPs and ports, detects open ones using TCP connect scanning, grabs service banners, performs OS detection, and reports results in a clean colored table. Built as part of learning systems programming and network tooling in Go.
This project contains two separate binaries:
- netaudit — scans a network once and exits
- netaudit-monitor — continuously monitors a network and alerts on changes
- TCP connect scanning with concurrent worker pool
- Banner grabbing — identifies what service is running on each open port
- OS detection from banners — labels devices as Ubuntu, Debian, MikroTik, Windows, iOS, Embedded/IoT etc
- Reverse DNS lookup — resolves hostnames for discovered devices
- Live progress bar during scanning
- Colored, sorted summary table output
- Port profiles — scan by name instead of numbers
- Verbose mode — show closed and filtered ports
- Rate limiting — control probes per second
- Save results to
.json,.csv, or.txt - Network state persistence — monitor remembers the network between restarts
- Auto-named state files per network — switch networks without conflicts
netaudit/
├── cmd/
│ ├── scanner/
│ │ └── main.go → network scanner entry point
│ └── monitor/
│ └── main.go → network monitor entry point
├── scanner/
│ ├── scanner.go → TCP scanning, banner grabbing, worker pool
│ ├── ip.go → IP parsing, range generation, reverse DNS
│ ├── result.go → result struct, table output, file saving
│ └── os.go → OS detection from banners
├── monitor/
│ ├── monitor.go → change detection, monitoring loop
│ └── state.go → network snapshots, state persistence
├── go.mod
├── go.sum
└── README.md
- Go 1.21 or higher
- Linux / macOS
- Network access to target range
# Clone the repo
git clone https://github.com/rjeff-sudo/netaudit.git
cd netaudit
# Fix GOPATH if needed (especially on shared/lab machines)
export GOPATH=$HOME/go
export GOMODCACHE=$HOME/go/pkg/mod
# Make it permanent
echo 'export GOPATH=$HOME/go' >> ~/.bashrc
echo 'export GOMODCACHE=$HOME/go/pkg/mod' >> ~/.bashrc
source ~/.bashrc
# Build both tools
go build ./...
go build -o netaudit ./cmd/scanner
go build -o netaudit-monitor ./cmd/monitorGo will automatically download all dependencies on first build.
# Scan a single machine
./netaudit -target 192.168.1.1 -ports 22,80,443 -workers 100
# Scan a network range
./netaudit -target 192.168.1.1-192.168.1.254 -ports 22,80,443 -workers 200
# Use a port profile
./netaudit -target 192.168.1.1-192.168.1.254 -ports common
./netaudit -target 192.168.1.1-192.168.1.254 -ports web
./netaudit -target 192.168.1.1-192.168.1.254 -ports db
./netaudit -target 192.168.1.1-192.168.1.254 -ports ssh
# Scan all ports on a single machine
./netaudit -target 192.168.1.1 -ports 1-65535 -workers 500
# Rate limited scan
./netaudit -target 192.168.1.1-192.168.1.254 -ports common -rate 100
# Save results to file
./netaudit -target 192.168.1.1-192.168.1.254 -ports common -output results.json
./netaudit -target 192.168.1.1-192.168.1.254 -ports common -output results.csv
# Verbose mode (show closed ports)
./netaudit -target 192.168.1.1 -ports common -v| Flag | Default | Description |
|---|---|---|
-target |
required | IP or range (e.g. 192.168.1.1 or 192.168.1.1-192.168.1.254) |
-ports |
common |
Port range, list, or profile (common/web/db/ssh) |
-workers |
100 |
Number of concurrent workers |
-timeout |
1 |
Connection timeout in seconds |
-rate |
0 |
Max probes per second (0 = unlimited) |
-output |
`` | Save results to file (.json, .csv, .txt) |
-v |
false |
Verbose — show closed ports |
| Profile | Ports |
|---|---|
common |
21, 22, 23, 25, 53, 80, 110, 111, 135, 139, 143, 443, 445, 993, 995, 1723, 3306, 3389, 5900, 8080 |
web |
80, 443, 8080, 8443, 8000, 8888 |
db |
3306, 5432, 6379, 27017, 1433, 5984 |
ssh |
22, 2222, 521 |
# Monitor a network every 60 seconds
./netaudit-monitor -target 192.168.1.1-192.168.1.254 -ports 22,80,443 -workers 200 -interval 60
# Monitor every 20 seconds
./netaudit-monitor -target 192.168.1.1-192.168.1.254 -ports 22,80,443 -workers 200 -interval 20
# Use a custom state file
./netaudit-monitor -target 192.168.1.1-192.168.1.254 -ports 22,80,443 -state office.json
# Monitor a different network (state files are auto-named per network)
./netaudit-monitor -target 10.0.0.1-10.0.0.254 -ports 22,80,443 -workers 200 -interval 60| Flag | Default | Description |
|---|---|---|
-target |
required | IP or range to monitor |
-ports |
22,80,443 |
Ports to monitor |
-workers |
100 |
Number of concurrent workers |
-timeout |
1 |
Connection timeout in seconds |
-interval |
60 |
Scan interval in seconds |
-state |
auto | State file path (default: auto-named from target) |
Scanning 254 IP(s) across 3 port(s) with 200 workers...
HOST IP PORT STATUS SERVICE OS
──────────────────────────────────────────────────────────────────────────────────────────
- 192.168.89.2 22 open SSH-2.0-ROSSSH MikroTik RouterOS
80 open - -
- 192.168.89.12 80 open Server: Caddy Linux (Caddy)
443 open - -
- 192.168.89.13 22 open SSH-2.0-OpenSSH_9.2p1 Debian Debian
- 192.168.89.165 22 open SSH-2.0-dropbear_2015.67 Embedded/IoT
80 open Server: GoAhead-Webs Embedded/IoT
LAP-092 192.168.89.190 22 open SSH-2.0-OpenSSH_9.6p1 Ubuntu Ubuntu
80 open Server: Apache/2.4.58 (Ubuntu) Ubuntu
──────────────────────────────────────────────────────────────────────────────────────────
Found 121 open port(s) across 62 host(s)
--- Network Monitor Started ---
Target: 192.168.89.1-192.168.89.254 | Interval: 20s | State: state_192_168_89_1_192_168_89_254.json
[*] No previous state found. Establishing baseline...
[+] Baseline established — 63 device(s) found
[15:22:30] Scanning...
[15:22:33] 2 change(s) detected:
[NEW DEVICE] 192.168.89.88:22 -> SSH-2.0-OpenSSH_9.6p1 Ubuntu
[LOST DEVICE] 192.168.89.34:80 -> Server: Apache/2.4.58 (Ubuntu)
[15:22:50] Scanning...
[15:22:53] No changes detected
The scanner identifies operating systems from SSH and HTTP banners:
| Banner | Detected OS |
|---|---|
SSH-2.0-OpenSSH_x.x Ubuntu |
Ubuntu |
SSH-2.0-OpenSSH_x.x Debian |
Debian |
SSH-2.0-ROSSSH |
MikroTik RouterOS |
SSH-2.0-dropbear |
Embedded/IoT |
Server: Microsoft-IIS |
Windows Server |
Server: GCDWebServer |
iOS |
Server: GoAhead-Webs |
Embedded/IoT |
Server: Caddy |
Linux (Caddy) |
Server: Apache |
Linux (Apache) |
Server: nginx |
Linux (Nginx) |
Only scan networks and devices you own or have explicit permission to scan. Unauthorized port scanning may be illegal under computer misuse laws in your country.
- Go — systems programming language
- fatih/color — terminal colors
- schollz/progressbar — live progress bar
Jeff — Zone01 Kisumu