Quick Scan
Sweeping the subnet and how device classification works.
Quick scan is the first pass: it discovers who's on the network and takes an educated guess at what each host is, without touching every port.
- Confirm the network range. The Network field auto-fills from your default route (e.g.
192.168.1.0/24) — override it to scan a VLAN or a different interface's subnet. - Leave mDNS on. The mDNS checkbox runs an 8-second passive Bonjour/Avahi browse alongside the sweep — it's the most reliable way to get real names for phones and Apple/Android/IoT gear.
- Press Quick Scan. The engine ARP-sweeps (or ping-sweeps) the range concurrently, then per live host: resolves a hostname, reads MAC + vendor, grabs TTL, and probes a short list of signature ports.
- Read the table as it fills in. Rows stream in live — IP, hostname, MAC, vendor, TTL, quick port hits, and a first-pass device type with its color and icon.
How a host gets its type
Classification runs signature layers in order of confidence, so a strong signal from one layer overrides a weaker guess from another:
| # | Signal | Example |
|---|---|---|
| 1 | Definitive port hit | Port 554/37777 → IP Camera, vetoes a router guess |
| 2 | MAC vendor | Apple OUI → iPhone/iPad; Hikvision OUI → IP Camera |
| 3 | Hostname keyword | living-room-plug → Smart Appliance |
| 4 | mDNS service type | _googlecast._tcp → Smart TV / Media |
| 5 | Port signature set | 135+139+445+3389 open → Windows PC |
| 6 | TTL fallback | TTL 64 → Linux/Unix, TTL 128 → Windows, TTL 255 → Router |
A handful of vendor overrides exist for devices that run Linux but aren't general-purpose Linux boxes — UniFi gear, Synology/QNAP NAS units, MikroTik/OpenWrt routers — so they land in the right bucket instead of a generic Linux / Unix.