Device Fingerprinting

Vendor lookup, hostname resolution, and smart-home UDP probing.

MAC → vendor

Vendor lookup tries the mac-vendor-lookup and manuf libraries first, then falls back to a hardcoded table of 300+ OUI prefixes covering Apple, Samsung, Huawei, Xiaomi, Espressif, TP-Link, Ubiquiti, Hikvision/Dahua, and common VM hypervisors (VMware, VirtualBox, QEMU, Hyper-V) — so vendor identification still works fully offline.

Hostname resolution (in priority order)

  1. mDNS discovery table — collected passively during the 8-second Bonjour browse, zero extra latency, best coverage for phones and IoT.
  2. NetBIOS — nbtstat -A on Windows, raw UDP/137 elsewhere; strongest for Windows PCs, NAS boxes, and printers.
  3. mDNS unicast/multicast PTR — direct reverse query on 5353.
  4. LLMNR — link-local PTR query on 5355, Windows-native.
  5. Reverse DNS — last resort, only useful if your router publishes PTR records.

Smart-home UDP probing

Because Wi-Fi bulbs, plugs, and sensors rarely open a listening TCP port, the scanner sends protocol-specific UDP probes so Yeelight, Xiaomi miio, and Tuya-local devices still get caught:

PortProtocolCatches
1982/udpYeelight SSDP M-SEARCHBulbs, strips, ceiling lights — reply includes model + name
54321/udpmiio hello packetXiaomi/Mi Home plugs, fans, robot vacuums
6668/udpTuya local discoveryGeneric Tuya-based smart devices (Gosund, generic switches)