Quick Scan

Sweeping the subnet and how device classification works.

Quick scan is the first pass: it discovers who's on the network and takes an educated guess at what each host is, without touching every port.

  1. Confirm the network range. The Network field auto-fills from your default route (e.g. 192.168.1.0/24) — override it to scan a VLAN or a different interface's subnet.
  2. Leave mDNS on. The mDNS checkbox runs an 8-second passive Bonjour/Avahi browse alongside the sweep — it's the most reliable way to get real names for phones and Apple/Android/IoT gear.
  3. Press Quick Scan. The engine ARP-sweeps (or ping-sweeps) the range concurrently, then per live host: resolves a hostname, reads MAC + vendor, grabs TTL, and probes a short list of signature ports.
  4. Read the table as it fills in. Rows stream in live — IP, hostname, MAC, vendor, TTL, quick port hits, and a first-pass device type with its color and icon.

How a host gets its type

Classification runs signature layers in order of confidence, so a strong signal from one layer overrides a weaker guess from another:

#SignalExample
1Definitive port hitPort 554/37777 → IP Camera, vetoes a router guess
2MAC vendorApple OUI → iPhone/iPad; Hikvision OUI → IP Camera
3Hostname keywordliving-room-plug → Smart Appliance
4mDNS service type_googlecast._tcp → Smart TV / Media
5Port signature set135+139+445+3389 open → Windows PC
6TTL fallbackTTL 64 → Linux/Unix, TTL 128 → Windows, TTL 255 → Router

A handful of vendor overrides exist for devices that run Linux but aren't general-purpose Linux boxes — UniFi gear, Synology/QNAP NAS units, MikroTik/OpenWrt routers — so they land in the right bucket instead of a generic Linux / Unix.