Deep Scan

Full port sweep, SNMP, NetBIOS, UPnP, and OS fingerprinting.

Deep scan targets specific hosts — one selected row, or every host from the last quick scan — and replaces the light signature probe with a full workup:

01

Port & Service Sweep

Scans the full range, grabs a banner off every open port, and maps well-known ports to a service label with best-effort version parsing.

02

SNMP Probe

Sends a hand-built SNMPv1 GetRequest for sysDescr and sysName against the public community string — no pysnmp dependency.

03

NetBIOS + UPnP

Resolves a NetBIOS name where available and fetches the UPnP device-description XML from anything that answered the SSDP sweep.

04

OS Fingerprint

Combines TTL distance-from-power-of-two with open-port fingerprints to produce a best-effort OS guess string.

Reading the results window

Double-clicking a row (after a deep scan has run on it) opens a per-host window with five tabs:

TabContents
OverviewIP, hostname, MAC, vendor, device type, TTL, OS guess, NetBIOS name, mDNS services, SNMP + UPnP fields
Open PortsSortable table of port / service / version-banner
BannersRaw banner text captured per port, for manual inspection
OS / IdentityTTL, NetBIOS, SNMP fields, and full UPnP/SSDP detail in one view
Raw JSONThe complete deep-scan result object, for scripting or archiving

Scope tip — Deep-scanning every host on a large subnet takes real time — a full 65535-port sweep per device adds up. Use Deep (Selected) to investigate one suspicious host instead of Deep Scan All unless you actually need whole-network coverage.