Device Fingerprinting
Vendor lookup, hostname resolution, and smart-home UDP probing.
MAC → vendor
Vendor lookup tries the mac-vendor-lookup and manuf libraries first, then falls back to a hardcoded table of 300+ OUI prefixes covering Apple, Samsung, Huawei, Xiaomi, Espressif, TP-Link, Ubiquiti, Hikvision/Dahua, and common VM hypervisors (VMware, VirtualBox, QEMU, Hyper-V) — so vendor identification still works fully offline.
Hostname resolution (in priority order)
- mDNS discovery table — collected passively during the 8-second Bonjour browse, zero extra latency, best coverage for phones and IoT.
- NetBIOS —
nbtstat -Aon Windows, raw UDP/137 elsewhere; strongest for Windows PCs, NAS boxes, and printers. - mDNS unicast/multicast PTR — direct reverse query on 5353.
- LLMNR — link-local PTR query on 5355, Windows-native.
- Reverse DNS — last resort, only useful if your router publishes PTR records.
Smart-home UDP probing
Because Wi-Fi bulbs, plugs, and sensors rarely open a listening TCP port, the scanner sends protocol-specific UDP probes so Yeelight, Xiaomi miio, and Tuya-local devices still get caught:
| Port | Protocol | Catches |
|---|---|---|
1982/udp | Yeelight SSDP M-SEARCH | Bulbs, strips, ceiling lights — reply includes model + name |
54321/udp | miio hello packet | Xiaomi/Mi Home plugs, fans, robot vacuums |
6668/udp | Tuya local discovery | Generic Tuya-based smart devices (Gosund, generic switches) |