What's new
The current version is 0.22.0. Every release and what changed in it, newest first.
0.22.0 · 2026-10-08
The trial shows what SubnetSleuth does on a real network without inventorying a whole one.
Changed
- The trial, and a test licence, collect from one network and keep up to 25 devices. The first scan names the
network (a single subnet of up to 256 addresses) and the copy remembers it; later scans and pulls stay inside it,
and a scan cannot follow neighbours out of it. A project keeps at most 25 devices (network devices and hosts
together): polling stops at 25, and what a step finds beyond that is not kept; the app says how many were found
and offers a licence. A pull keeps only the records inside the network, after a first scan has named it. Deep
scans, host inspection and config capture leave addresses outside it alone. What a project already holds is
never cut: the sample network, or a project made with a licence, opens and keeps everything. A paid licence lifts
both limits. The licence window, the licence agreement and
subnetsleuth license statussay so. - On the command line, a scan or sweep that names more than one network, or a second network, stops with status 3 and says what the trial covers.
0.21.0 · 2026-10-08
SubnetSleuth becomes a product you buy: a 14-day trial, licence keys, and a home at subnetsleuth.com. From this version it is proprietary software under the SubnetSleuth End User Licence Agreement; versions up to 0.20.0 remain available under the MIT licence they were released with.
Added
- A 14-day trial, then a licence. Everything works for 14 days from the first run of the app or the command line. After that, what collects or asks needs a licence: new scans and rescans (a scheduled rescan or pull is skipped and logged, never left waiting on a message box), crawls and ping sweeps, pulls from connections, deep scans, host inspection, config capture, listening for syslog and traps, Ask AI questions and model tests, and the Claude Desktop connector's tools. What never needs one: opening, viewing and editing projects and their notes, saving, exporting, comparing, checking against an asset list, the query console and the REST API, importing a DHCP lease file, looking after credentials, connections and AI providers, and Help. Nobody is locked out of their own data.
- Licence keys from subnetsleuth.com/pricing: a signed key (
SS1.…) shown as soon as the checkout is paid and downloadable as a.licfile, checked on the computer itself — activating sends nothing anywhere. A Pro licence is for one person on up to three devices; Team and Enterprise keys carry their number of seats. A licence covers every version released while it runs, and those versions keep working after it ends; versions released later need a renewal. A test licence (from a test-mode checkout) is marked as such and simply stops when it ends. - Help ▸ Licence… shows the licence or the trial and takes a key, pasted (line breaks and spaces from an email do no harm) or with Load licence file…; Buy a licence opens the pricing page and Remove licence frees it to move to another computer. The status bar shows where it stands (in amber for the trial's last three days and once something is refused; a click opens the window), so does Help ▸ About, and the window opens at start-up when the trial has ended. An action that is refused says why, with Buy a licence and Enter key…, and goes ahead as soon as a key is activated.
subnetsleuth license status [--json] | activate KEY_OR_FILE | remove. A command that needs a licence prints why and exits with status 3 when there is none; the licence is shared with the desktop app (license.jsonbeside the saved credentials).THIRD-PARTY-NOTICES.md: every open-source component in the builds, with its version, licence and home page (tools/third_party_notices.py), installed with the app beside the licence agreement.
Changed
- SubnetSleuth lives at subnetsleuth.com. Help ▸ Check for updates reads subnetsleuth.com/version.json (still
only when asked, and carrying nothing but the version number) and opens the download page there; About, the
installer, the Claude Desktop extension (
.mcpb) and the package metadata point at subnetsleuth.com and its download, changelog and support pages. - The licence: from 0.21.0 SubnetSleuth is proprietary software under the SubnetSleuth End User Licence
Agreement (
LICENSE), which the installer shows before installing. Versions up to 0.20.0 remain available under the MIT licence they were released with. - The installed and portable desktop app keeps the LGPL libraries paramiko and ldap3 as their own source files in the program folder, beside Qt's, so each can be replaced as its licence allows.
- CI runs the test suite once, on Linux with Python 3.12, for each push and pull request; the full test matrix, the builds and the desktop self-test run for release tags and manual runs.
0.20.0 · 2026-10-08
Asking about the network no longer needs Claude Code: a Claude plan works through Claude Desktop, Cowork and claude.ai, and Claude (or another vendor's models) can be asked through an API.
Added
- Claude Desktop and Cowork read the project. SubnetSleuth is a local connector (Model Context Protocol over
stdio): Connections ▸ Use your Claude plan ▸ Add to Claude Desktop or
subnetsleuth mcp installadds it to Claude Desktop's settings (keeping the rest of the file and a backup; the Microsoft Store build's own settings file too), and each release shipsSubnetSleuth-<version>.mcpb, a single-click desktop extension an organisation can allow-list. Claude, in a chat or in Cowork, on the user's own plan and sign-in, can then read the project last opened or saved in the app: a briefing, and list, read and search over the exported data, read-only. The five ready-made questions are offered as the connector's prompts.subnetsleuth mcp serve|install|remove|status|show. - Hand-off to claude.ai and Cowork: a Markdown briefing to attach to a chat or a Claude Project (the prompt is
copied and claude.ai opened), or a folder holding the full export and its instructions for Cowork;
subnetsleuth ask --handoff chat|cowork. Nothing is sent by SubnetSleuth. - AI providers: the assistant asks through an API as well as through Claude Code. Claude through Anthropic's
API (an API key, or an Anthropic Console sign-in profile), Claude Platform on AWS, Amazon Bedrock (AWS profile or
SSO, or a Bedrock API key), Google Cloud Vertex AI (Google Cloud sign-in or a service account key file) and
Microsoft Foundry (Sign in with Microsoft through Entra ID, the Azure CLI's account, or a key); and OpenAI,
Azure OpenAI (Entra ID or a key), Google Gemini, Mistral AI, xAI, OpenRouter, Ollama and any OpenAI-compatible
service. Each offers its current models and effort levels, lists what the account can use (Refresh) and takes
any other name; Test does a one-word round trip. Providers are saved in the vault beside connections and
credentials (an API key is an ordinary saved credential; the cloud sign-ins are each cloud's own, so no password
is stored), managed in Connections ▸ AI providers or with
subnetsleuth ai types|list|add|edit|remove|test| models|default|check, and shared between the app andsubnetsleuth ask --provider. - A thorough question to an API model gives it three read-only tools over the exported project (list, read, search) and runs the tool loop in SubnetSleuth; nothing else is offered to the model.
Changed
- The Ask Claude panel is now Ask AI: Ask with chooses Claude Code or a saved AI provider, and Use your Claude plan opens the Claude Desktop, Cowork and claude.ai options. Kept answers record how they were asked.
Security
- Questions and keys go only to the provider's own address or the one saved with it, over HTTPS (plain HTTP only to
this computer, or to an address marked as a trusted lab). Every client is built with an explicit address and
sign-in, so
ANTHROPIC_BASE_URL,OPENAI_BASE_URLor an API key in the environment cannot redirect a question or a key. A model's tool requests are checked against each tool's schema; a file is one of the exported names, never a path. The status line checks that a key can be read without reading it, so only a question or a test is recorded as a use of the key.
0.19.0 · 2026-10-08
From a first pull of a real Meraki dashboard: the platform's devices and clients were read, but not identified as network gear and assets, its subnets did not reach the scan, and the map of a large network overlapped.
Added
- Scan what a pull found. After a pull, the internal subnets the platform serves (VLANs, DHCP scopes,
interface networks) join the project's scan ranges and are swept, and the devices it manages are polled
over SNMP with their neighbours followed — one scan inventories everything the pull pointed at, and later
rescans include it. The app offers it when a pull finishes (Start scan, Review in New scan…, or
Not now, with an option to always start it; also in Preferences ▸ After a pull); the command line does
it with
pull --scan(--snmp-credential,--no-identify). A full scan also identifies every host and checks its open ports. Subnets behind site-to-site tunnels (which may be a partner's or a cloud provider's) and summaries wider than a /16 are listed and left out; a re-pull with nothing new starts nothing. -
A platform's cabling is drawn on the map: the LLDP/CDP links it reports between the boxes it manages (switch to switch, switch to access point, appliance to switch), and each client on the switch port or access point it was seen on. A network known only from its dashboard is no longer a set of unconnected boxes.
-
The clients a platform reports are identified: what a dashboard says about a client — its device type ("iPhone SE", "Printer", "Cisco IP Phone", "Apple TV"), operating system ("Windows 11", "Android") and maker — is weighed with everything else the scan found, so phones and tablets, PCs and laptops, printers, desk phones, cameras and media devices come out as such (citing the platform as the evidence). A new type, Phone / tablet, has its own icon and group; the desk-phone type is now called IP phone. A management platform's or Windows' own word on a device still outranks these.
-
The map stays readable on large networks. No device, host or label is drawn on top of another in any view or layout — on a simulated campus of about 1,600 nodes the overlapping pairs went from about 1,300 to none, and laying it out takes a fifth of a second. Redundant pairs (HA firewalls, core and distribution pairs) sit side by side; each switch's hosts and subnets pack into a grid under it, joined by one bus rather than a fan of lines; very wide tiers wrap; devices with no known cabling are gathered in one tidy group; and zoomed far out, a grid shows as a single "38 hosts" badge under its switch while the network devices keep their names — endpoints collapse first, the network last. Positions you placed by hand are never moved, and the draw.io export carries the same layout.
Changed
- Network gear known from a platform, or identified but not polled, is listed under Network devices (with what it is known from and its model, serial and firmware), not among the hosts.
- A security appliance with no management address in the API (a Meraki MX) is placed on the map at its VLAN gateway address.
0.18.0 · 2026-10-08
One place for access, one way to do each thing. Everything SubnetSleuth signs in with, and every system it reads from, is now saved once and used everywhere — by the desktop app and the command line alike.
Added
- Connections and credentials (Connections ▸ Connections and credentials, Ctrl+Shift+K, and a toolbar button). Credentials — SNMP community or v3 user, SSH account (key file with its passphrase kept apart), Windows / domain account, web or API sign-in, API key, DNS TSIG key — are saved once and chosen wherever a job signs in; one domain account can serve Active Directory, every Windows DNS/DHCP server and host inspection. Connections — firewalls, firewall managers, cloud dashboards, Active Directory, Windows DNS/DHCP servers, DNS zones, vCenter, DHCP export files — each name their settings and the credential they use, with Test (sign in and read one small thing), Pull, and Pull all (Ctrl+Shift+P). The list shows when each connection was last pulled and what came back, and which credentials each uses.
- The command line uses the same list:
subnetsleuth credentials list|add|edit|remove|test,subnetsleuth connections sources|list|add|edit|remove|test|scopes,subnetsleuth pull -m MAP(saved connections,--all, or a one-off--source), and--credential/--saved-credentialsoncrawl,--ssh-credential/--windows-credential(with--win-https,--win-insecure) oninspect,--credentialoncapture. A secret is asked for or read fromenv:NAME, never taken as a plain value by the new options.credentials testruns the same check as the app's Test button. - A credential can be limited to networks (in its editor, or
credentials add|edit --networks), so one that belongs to a site or customer is never sent anywhere else, however wide a scan's ranges. - VMware vCenter / ESXi is a connection like any other: ESXi hosts and every VM (all its addresses, guest OS, power state, size, host and cluster), lined up with the scan by MAC, listed on the Sources page, pulled again or removed like the rest, and saved with the project (it was not before).
- DHCP lease export files go through the same path as a live DHCP server (File ▸ Import DHCP leases from
a file, or
pull --source dhcp-file): the same matching by MAC, the same rules for leases nobody holds, and DHCP scopes recorded for every lease source, not only files. The Sources page lists every lease and where it landed. - Scheduled rescans can pull every connection afterwards.
- Every use of a saved credential is written to the log (which credential, for what, against what — never the secret), and the log masks secrets in every line, from SubnetSleuth or the libraries it uses.
Changed
- Menus have one entry per job. A new Connections menu; Deep scan, Inspect hosts, Capture configs and Listen moved under Scan; panels (Details, Activity, Network tools, Ask Claude) are opened from View only; the theme lives in Preferences only; the right-click menu and the Details panel's Actions button offer the same actions in the same order. The Platforms page is now Sources.
- New scan picks from the saved SNMP credentials (the one-off community box is gone), and a rescan uses exactly the credentials the project was scanned with — never every saved one.
- Inspect hosts and Capture configs pick saved SSH and Windows credentials instead of asking for a password each time. Inspection sends a credential only to hosts inside the project's ranges that look like the right kind of system, and WinRM uses the same defaults everywhere (HTTP 5985 with NTLM message encryption; the certificate is checked over HTTPS unless you accept an untrusted one).
- Connection settings are consistent across sources: every one has Host (name or address, optionally
:port) and Accept an untrusted (self-signed) certificate; API keys areapi_keyeverywhere; a separate port setting becamehost:port. Saved connections are upgraded when they move into the vault. - One error explanation for every source, in the app and on the command line, with any credential value masked out of it.
- SNMP credentials, remembered platform connections and their protected secrets saved by 0.17 or earlier move
into the new vault (
vault.json) on first run. - The Windows DNS/DHCP connection no longer offers CredSSP (it hands the whole credential to the server).
- Operating-system families are one vocabulary: Cisco IOS and Apple iOS are told apart (
cisco-ios,apple-ios; a filter oniosmatches neither any more), IOS-XE, AOS-CX, FortiOS and the rest get their own family, and every source (SNMP, nmap, banners, platforms, vSphere, Active Directory) maps through the same rules. Saved projects are converted when opened. - One name ranking for every source: a DNS name beats a platform's, which beats the name a DHCP client gave itself, which beats NetBIOS and mDNS; reverse DNS no longer overwrites a name you typed.
- Compliance findings name the SNMP version a device answered, never a credential's name.
Removed (command line)
subnetsleuth platform list|scopes|pull: useconnections sources,connections scopesandpull.subnetsleuth vmware: usepull --source vmware -S host=… --credential …(or a saved connection).crawlno longer falls back to the communitypublic, or readsSUBNETSLEUTH_COMMUNITYby itself: with no credential at all it stops and says how to give one (-C publicand-C env:SUBNETSLEUTH_COMMUNITYstill work).
Fixed
- An SNMPv3 credential whose key was missing (an unset environment variable, a secret saved under another Windows account, a v3 user saved without keys) was silently sent with no authentication or no privacy. It is now refused, with the reason.
- A saved secret that could not be read (settings copied from another PC or account, common in portable mode) was used as an empty value and still shown as saved. It is now reported, and the credential is marked cannot be read here.
- API tokens could follow a redirect to plain HTTP or to another port of the same host. Credentials now go only to the platform's own origin (scheme, host and port), and a request body never follows a redirect elsewhere.
- An SSH key passphrase was sent as a login password when key authentication was refused; it now only
unlocks the key on this computer. SSH no longer offers the operator's own
~/.sshkeys or agent to devices. - Mask mode sent Cisco-format MACs and IPv6 addresses to Claude unmasked, and the credential column (only its name, never a secret) went into Claude's briefing although it was meant to be hidden.
- A host inspection wiped what other sources had recorded about the host (VM name, hypervisor, platform serial, previous MACs), and a role reported by Windows itself, a management platform or vSphere could be overridden by a guess from open ports (a domain controller shown as a web server).
- A DHCP lease nobody holds (free, offered, backup) could add a host, and a lease with an all-zero MAC could replace a good MAC and mark the address re-assigned.
- A placeholder serial such as "To be filled by O.E.M." could match two different machines.
- A project with both IPv4 and IPv6 hosts could not be exported to CSV.
- The Resolve names from reverse DNS preference never reached the New scan dialog (it was saved under another name), and rescans ignored the Preferences altogether.
- A host whose only clue was an open SNMP port was typed as "network", which is not a type the app knows.
- A setting written as text
"false"(a config file, the command line) was read as true by several connections, turning certificate checks off. - Claude's "model not available" error was sometimes reported as a bare
error_during_execution. - Older project files that held part of an SNMP community in a credential label are cleaned when opened.
- The API server rejects requests for another host name (DNS rebinding) and will not listen beyond this computer without a token. Claude Code now runs with only the environment it needs, not every secret in yours.
0.17.0 · 2026-10-08
Added
- Pull from firewalls and management platforms (File ▸ Import ▸ Firewall / management platform,
subnetsleuth platform pull): read-only connectors for Cisco Meraki, Cisco Security Cloud Control (CDO), Cisco Secure Firewall Management Center (FMC), Fortinet FortiGate, Fortinet FortiManager, Palo Alto Networks firewall (PAN-OS), Palo Alto Networks Panorama, Check Point Security Management, SonicWall (SonicOS), Sophos Firewall. Each reads what the platform already knows — managed devices with model, serial, firmware, status and site; clients with MAC, address, name, OS, user, VLAN and switch port or SSID; interfaces, subnets, ARP and DHCP tables, neighbours, routes, tunnels and named address objects — and lines it up with what the scans found. Every request is checked against the connector's read-only list before it is sent, and credentials only ever go to the platform's own hosts. Connections can be remembered with their secrets in Windows DPAPI or the system keyring. - Records are matched to the scan by serial, MAC, address and name, so a platform's switch is the same record as the polled switch. Clients and DHCP leases follow the MAC: a host the scan left at an old address is marked as moved, and an address now used by a different machine is recorded as re-assigned before taking the new MAC (the duplicate-and-mislabel problem a DHCP network gave repeated scans).
- Active Directory, DNS and DHCP (File ▸ Import ▸ Active Directory / DNS / DHCP): read-only connectors for Active Directory over LDAPS (computer accounts with OS and last sign-in, domain controllers, AD sites and subnets, authorised DHCP servers, AD-integrated DNS records), a Windows DNS/DHCP server over WinRM (DHCP scopes, active leases, reservations and options; DNS zones) and any DNS server by zone transfer. They name hosts and subnets, type domain controllers and DHCP servers, and place hosts from active leases, through the same matching as the firewall platforms. Nothing secret is requested and only computers are read.
- Site-to-site tunnels on the map: every tunnel a platform reports is drawn from its firewall to the far end (a box already on the map when it can be recognised, otherwise a remote-site node), coloured by state, with the networks behind it on the logical view; a tunnel reported from both ends is one link, and one that is down is a finding.
- Platforms page listing every record each platform reported and where it landed on the map; a Platforms tab in a device's or host's details; new Needs attention findings for managed devices reported offline, reads an account was not allowed to make, hosts that moved and re-assigned addresses.
- Ask Claude (Tools ▸ Ask Claude,
subnetsleuth ask): questions about the project answered by Claude through your own Claude Code, signed in to your own Claude account (including single sign-on) — SubnetSleuth never handles the sign-in. Model and effort selectors (Claude Haiku 5.5 by default; Sonnet 5.5, Opus 5.5, Fable 5.1, the tier aliases, or any model id), a Test round trip, ready-made analyses (explain the network, what the platforms add, asset-register clean-up, models and firmware, questions for the previous owner), a thorough mode in which Claude searches a read-only export of the full project, optional masking of addresses, MACs, serials and names, and answers that can be kept with the project.subnetsleuth claude status|login|test|modelsmanage the sign-in from the command line.
Changed
- A management platform's own view of what a device is (firewall, switch, access point…) now counts as strong evidence when hosts are typed; subnets show the name a platform gives them when you have not named them yourself.
0.16.2 · 2026-10-06
Fixed
- The desktop app no longer grows without limit during a long scan. While a scan ran, the window refreshed itself every few seconds on a background thread that kept a full copy of the inventory, and none of those threads was ever freed — nor the scan worker, the working copy made before each job, or the crash-recovery copy written every couple of minutes. Memory grew with every refresh: a scan of ~1,300 hosts over 83 subnets reached 12 GB. Finished background jobs are now released with everything they held, so memory levels off a few hundred MB above the size of the project however long the scan runs (measured on a simulated 1,374-host network: five back-to-back scans went from 465 → 1,030 MB after three scans to a flat ~225 MB).
0.16.1 · 2026-10-02
Changed
- Host discovery sets a packet-rate floor by default (
--min-rate 500). The-T4timing in 0.16.0 was not enough on its own: against a range of firewall-dropped addresses, nmap's congestion control still backs off until it is sending only a handful of packets a second, so an empty /24 took minutes. Giving discovery a rate floor bypasses that — a silent /24 now finishes in around ten seconds (measured ~4m40s → ~13s for a /24 of dropped addresses). The rate is still the Minimum discovery rate setting (New scan ▸ Options) /crawl --min-rate; lower it to 0 or a small value on a slow or fragile link, where too high a rate can drop live hosts.
0.16.0 · 2026-10-02
Much faster host discovery on large, mostly-empty networks.
Changed
- Host discovery no longer crawls on dead address space. The ping sweep now runs nmap with
aggressive timing (
-T4, so a silent address is given up on after about a second instead of ten) and probes a whole /24 at once (--min-hostgroup). A /24 of firewall-dropped addresses that used to take ten to fifteen minutes now finishes in tens of seconds, so sweeping several /16s is minutes rather than hours. The estimate shown before a large sweep is updated to match.
Added
- A Minimum discovery rate setting (New scan ▸ Options, or
crawl --min-rate PPS). Left at automatic by default; raising it puts a floor on nmap's discovery packet rate so a very large flat range is bounded by throughput rather than nmap's timeouts. On a fast internal network 500–2000 packets/sec is usually safe; too high a value on a slow link can drop live hosts.
0.15.0 · 2026-10-02
Better at telling network devices apart, and able to draw a topology even when the switches don't speak LLDP or CDP.
Changed
- Device types are worked out from evidence, not just the model string. A device is now classified from the capabilities it (or its neighbours) advertise over LLDP/CDP — bridge, router, wireless access point — together with its bridge forwarding table and physical-port count, before any guess from its description. Crucially it no longer falls back to router just because the SNMP routing service bit is set (that bit is on almost every managed switch), so a switch or access point whose model isn't recognised is no longer mislabelled as a router. A second pass types a device the tool couldn't place at all from how its neighbours describe it.
Added
- Topology from the MAC tables. When LLDP and CDP are switched off (or not readable), the map used to collapse into disconnected subnet groups. SubnetSleuth now reconstructs the switch-to-switch links from the bridge forwarding tables — the port through which a switch learns another switch's address is the port facing it — so the map joins up from the MAC tables alone. Inferred links are drawn dashed to distinguish them from links a device actually reported, and the path tracer follows them.
- A Limited SNMP visibility finding: a managed device that answers SNMP but returns no LLDP/CDP neighbours, no MAC table and no routes is flagged, because that is the usual reason a topology comes out disconnected — an SNMP view or community that excludes those MIBs, or LLDP/CDP turned off.
0.14.0 · 2026-10-02
Changed
- The overview no longer shows Devices by role and Endpoints by type as two lists that
overlapped. It now splits everything by what it is: Network infrastructure — firewalls,
routers, switches and access points, wherever they were found, with the lighter part of each
bar the gear not yet polled over SNMP — and Endpoints by type — everything attached to the
network, in broad kinds (PCs, phones, printers, servers, …), with servers grouped into one row
since Server functions already breaks them down. Network gear by vendor, the spreadsheet
summary and the command-line summary use the same split, and the device and host lists gain a
hidden Kind column so you can filter with, for example,
group:servers.
Added
- An optional try well-known default communities step for a scan: after your own SNMP
credentials, SubnetSleuth can try the handful of factory-default community strings (public,
private, …) read-only, inside the same ranges as every other step. A device that answers one is
reported under Needs attention so you can change it — useful when you are taking over a
network with no documentation. In the New scan dialog, or
crawl --try-default-communities. - Authenticated Windows inspection now identifies the device type: reading the operating system's product type over WinRM tells a server, a domain controller and a workstation apart and sets the host's type with high confidence. The inspect dialog (now Inspect hosts) can also connect over HTTPS (WinRM 5986).
0.13.1 · 2026-10-01
Changed
- The sample network (Help > Explore the sample network) includes a deep scan of its intranet web server, so the Deep scan and Scripts tabs can be seen without running one.
- A deep scan lists its ports from low to high.
Added
tools/make_demo_video.pyrenders the demo video from the app itself.
0.13.0 · 2026-10-01
NetMap is now SubnetSleuth: the desktop app is SubnetSleuth.exe, the command line
subnetsleuth, and the repository github.com/kerbe42/subnetsleuth (the old address redirects).
Changed
- New projects are saved as
.sleuth..netmapprojects open and save as they are, and the installer associates both extensions with SubnetSleuth. - The installer upgrades a NetMap install in place: it installs into a SubnetSleuth folder and removes the old NetMap program folder, Start menu entry and desktop shortcut.
- On first start SubnetSleuth copies NetMap's settings: preferences, window layout, recent files
and saved SNMP credentials, which still decrypt. The SSH host keys NetMap recorded are carried
over too. A portable folder with
netmap-portable.inikeeps working. - Environment variables are now
SUBNETSLEUTH_*(for exampleSUBNETSLEUTH_COMMUNITY); the oldNETMAP_*names still work. - The config example is
subnetsleuth.toml.example; command-line defaults aresubnetsleuth.jsonandsubnetsleuth.html.
0.12.0 · 2026-10-01
Added
- Now: line in the Activity panel: the subnets, /24 blocks, address batches, devices and hosts the scan is working on at that moment, with Nmap's current stage and how long anything slow has been running (hover for the full list). Scans also log a "working on: …" line once a minute, so the command line shows progress too.
- Deep scan of chosen addresses: right-click a device or host, Tools ▸ Deep scan an address
with Nmap… (Ctrl+Shift+D), or
netmap deepscan IP… -m project. All 65,535 TCP ports, full service-version detection, OS detection and traceroute (Administrator/root), optional common UDP services, and Nmap'sdefault and safeinformation scripts. Results are kept in the project and shown on new Deep scan and Scripts tabs; ports and the OS guess also update the host.
Changed
- Ranges you enter are scanned in full, whatever their size. Ranges larger than a /20 get a warning
with a rough duration instead of being skipped. The size limit now applies only to subnets learned
from devices (Largest discovered subnet to sweep,
--sweep-max-size), andnetmap sweep --subnetno longer applies it. - Sweeps hand out /24 blocks from a shared queue, so a very large range does not create a task per block up front.
0.11.0 · 2026-10-01
Large networks (dozens of ranges, /16s) no longer lose results to nmap timed out.
Changed
- Ping sweeps run one
nmapper /24 of each range, eight at a time across all ranges, instead of onenmapfor a whole subnet. A /16 is 256 short runs, not one run that has to finish in time. - The port scan (Scan ports & service versions,
--port-scan) only goes to addresses that answer a ping. Addresses already seen answering in the same scan (sweep results, devices that answered SNMP) are not pinged again; the rest get a quicknmap -sncheck first. Addresses that answer nothing stay in the inventory but are not port-scanned, which is wherenmap -Pnused to spend its whole time limit. Untick Only port-scan addresses that answer a ping or pass--no-ping-first(config:ping_first = false) to scan every address found. - Every target ping sweep finishes before any fingerprinting starts.
- A target range larger than Largest subnet to sweep/probe is skipped with a warning (it was an info line), and the scan dialog lists such ranges before you start.
Added
- Nmap time limit per run (Preferences and the scan dialog),
--nmap-timeout MINUTESandnmap_timeoutin the config file: how long onenmaprun may take, default 30 minutes, 0 for no limit. - A run that reaches its limit keeps every host
nmaphad already reported. For a sweep, the block is pinged again with twice the time. For a port scan, only the addresses it had not finished are scanned again, in smaller batches with twice the time. Anything still unfinished is named in the log, and a subnet whose sweep did not finish is not marked swept, so the next sweep retries it. - Progress lines for long sweeps and port scans (blocks or addresses done so far).
Fixed
- Nmap ports per host in Preferences now reaches the scan; scans always used 200.
- The Scan ports & services checkbox showed "ports _services".
0.10.0 · 2026-09-30
Fixes from a review of the whole codebase, grouped by what they mean for someone using the tool.
Scope and read-only guarantees
- Every step that sends a packet - SNMP, ping sweeps, reverse DNS, host identification probes,
the optional
nmapservice and OS scans, SSH/WinRM/vCenter collection - now checks the same scope and exclusion lists before contacting an address, so Never touch and the scope apply to the whole scan, not only to SNMP polling. - Saved SNMP secrets on Linux/macOS are stored under a random identifier instead of one derived from the secret itself.
- The README now states exactly which steps send traffic, what each one sends, and how the scope, target ranges and exclusions bound them.
- Ping sweeps hand
nmaponly the part of a subnet that is inside the scope and outside every exclusion (an excluded range inside a swept subnet, or an excluded single address, used to be scanned and merely left out of the results). A target subnet wholly outside the scope is skipped with a warning. - Hosts imported from DHCP leases or vCenter, or kept from an earlier wider scan, are no longer probed, resolved or logged into when they fall outside the current scope.
- Running-configuration capture never sends a configuration-mode command. The FortiOS profile used to change the console paging setting, which is a logged configuration change; paging prompts are now answered instead. Any configuration-mode command is refused outright.
- Captured running configurations are stored with secrets redacted (SNMP communities, local passwords and hashes, pre-shared keys, RADIUS/TACACS keys, certificate blocks); the line stays so diffs still line up.
- SSH collection (host facts and configuration capture) checks host keys: the system
known_hostsplus a per-user store are consulted, a key is recorded on first sight, and a changed key stops the connection with a message naming the file to clear. - vCenter connections verify the TLS certificate by default;
--insecure(CLI) or the dialog's checkbox opts out for self-signed servers. - Authenticated inspection only tries SSH or WinRM where the port is open, never against appliance roles (controllers, cameras, printers, phones, lights-out management), so a read-only service account is not locked out by failed logons.
- The SSDP description document is only fetched from the address that announced it.
- The local read-only API no longer allows cross-origin reads from other web pages and takes
its token from the
Authorizationheader only. - Credential labels no longer embed any part of the community string (the default label used to carry its first characters into the project file, CSV and workbook exports).
- The syslog/trap listener records trap contents (trap name, interface, status) instead of the community string, and binds exclusively on Windows so it fails loudly rather than sharing a port with another listener.
Topology and identification accuracy
- The topology graph cache introduced in 0.9.0 now actually works (a loop variable overwrote its key), so refreshing a page no longer rebuilds the graph and re-profiles every host. Model changes that the cache must see (adding or removing hosts, subnets, devices) all invalidate it.
- Subnet gateways are the devices that route for the subnet (routing role, routes to other networks, or the active first-hop-redundancy owner), not every switch with a management address in it.
- Path tracing reaches endpoints announced over LLDP/CDP (access points, phones, servers) on their real access port instead of stopping at the gateway.
- Ports named "Port 1", "Port 24" (common on small-business switches) are no longer mistaken for port-channels, so hosts are placed on them and the port panel shows them.
- Q-BRIDGE forwarding tables map the forwarding-database id to the VLAN id (they differ on several vendors); ARP rows of invalid type are dropped; per-VLAN forwarding walks on IOS skip suspended VLANs and report when the VLAN cap truncates them.
- Two devices that share an address in a virtual range (container bridges, hypervisor default switches, first-hop virtual addresses) are no longer merged into one; merging needs a matching serial, chassis id, or name plus object id.
- SNMP table walks stop on agents that return non-increasing OIDs, retry once from the last row after a mid-walk timeout, and record a truncated table in the device's error list instead of presenting a partial table as complete.
- Routes are read from the address-family-neutral route table first, then the CIDR table, then the legacy table, so routers that only populate the newer table contribute routes; a malformed mask no longer discards the rest of a route table.
- LLDP local ports identified by MAC address are decoded and matched; PoE per-port status is matched by stack member and port, not by interface index.
- SNMPv1 credentials for old UPSes, PDUs and printers; address ranges (
a.b.c.d-e) in target files. - A rescan without the optional phases keeps a device's ports, operating system, management planes, functions and DNS name instead of blanking them.
- Host identification: vendor and product words are matched as whole tokens and only in the
fields that name a vendor (server header, certificate issuer), so "praxis" no longer means a
camera vendor and "pilot" no longer means lights-out management; a name seen from three
sources votes once; a NetBIOS answer without a unit id (file-sharing daemons on Linux and
storage appliances) no longer classifies the host as Windows; lights-out controllers are
bmc, cast and streaming devices are the newmediarole, and a Windows workstation with a web port is not promoted to a web server. BSD and hypervisor banners map to their own families. - Identification probes no longer starve at scale: concurrency is bounded per probe, so every host's answers are recorded (about one in eight was, on a 60-host test with slow answers).
- New reads: BACnet object name/vendor/model, NTP mode-6 variables, Modbus device id with the broadcast unit id first and complete frames.
- Findings: "Neighbour not polled" no longer fires for phones and access points announced over LLDP (they are listed as endpoints); VLAN host counts are distinct MACs; "Subnet not yet scanned" ignores point-to-point links and prefixes a polled device sits in; IPv6 hosts are not flagged as outside the address plan; a MAC seen on several addresses is reported instead of silently dropped. New checks: switch with a single uplink, overlapping subnets from different devices, spanning-tree root on an access switch or disputed between switches, VLAN mismatch across a link. Devices list a free-port count.
- Compliance: the spanning-tree default-priority check understands extended system ids (32768
- VLAN) and treats priority 0 as deliberate; the HTTP management finding is no longer hidden when Telnet is also open; the SNMP version check uses the protocol that answered, not the credential's label.
- Query language: quoted values may contain operators and the words and/or;
>and<compare IP addresses, sizes, durations and dates by value;port =searches services only; malformed queries raise a query error instead of crashing. - Compare: placeholder serials never produce a false "moved"; a host whose address changed is reported as readdressed rather than removed and added; the reboot check tolerates the 497-day uptime wrap. Asset-list check: serial and annotated name are compared the same way they are matched, and a listed device found only as an unpolled address says so.
- Exports: cells that start with a formula character are written as text in CSV and .xlsx; draw.io tooltips and edge labels are escaped for their HTML rendering; the hand-over workbook uses display names and adds Site/Owner/Status/Asset tag/Notes columns plus Findings, Compliance, Hardware support and Dependencies sheets.
- Layered layout wraps very wide layers of hosts under their parent switch (a 15,000-host estate laid out 2.6 million pixels wide before).
- DHCP import: the last lease block per address wins, inactive leases update existing hosts
only, inactive reservations are not reported active, and the
netshtable, the DHCP server XML export and Kea JSON are now accepted; an unrecognised file is reported instead of importing nothing.
Desktop app
- Nothing you typed or moved is lost any more: the last node drag before Save is written, the
last half-second of Notes typing is kept when you click another item or close, and the
project is no longer overwritten after a cancelled scan unless you had already saved it this
session. Three rotating backups (
.bak1-.bak3) are kept beside the project, with File ▸ Revert to saved and Tools ▸ Compare with the previous saved version. - Undo and redo (Ctrl+Z / Ctrl+Shift+Z) for note and role edits, Remove from project and Re-arrange.
- Crash recovery: while there are unsaved changes a recovery copy is written every two minutes and offered on the next start.
- Needs attention and Compliance rows can be acknowledged (right-click); acknowledged rows are hidden until you tick Show acknowledged, and the acknowledgement is saved with the project.
- Closing the window waits for every background job (scan, config capture, host inspection, vCenter discovery, update check) instead of tearing threads down mid-flight; starting a scan, opening or creating a project, or removing an item is blocked with a message while another job runs, and side jobs work on a copy of the inventory and merge on the UI thread.
- Large inventories: list sorting happens once in the model, saving, exporting and the scan's working copy run off the UI thread behind a wait cursor, and live scan updates are prepared in the background. On a 14,000-host project the Hosts page update went from about 5 s to 0.2 s, a header sort from 2 s to 0.2 s, and the spreadsheet export no longer freezes the window.
- The map keeps its selection when it rebuilds, a traced path stays zoomed to the path, and exported images are capped at 8,192 px with a real error if writing fails.
- Lists: hosts sort by address by default, the Type column shows the same labels as the dashboard and details, percentage bars stay readable at every fill level, empty lists say what to do next, exports remember the export folder, and the navigation pane fits its longest label. The port panel shows "Port N" interfaces and sizes itself correctly for small switches.
- Query results use the same fast table as the other pages; large subnets build their address grid once and cap the address list.
- Credential labels default to "v2c credential N"; the credentials list explains how to add the first one. Menu and toolbar wording names file formats rather than products.
- Uninstalling offers to remove the settings and saved credentials from the registry, removes the log folder, and an upgrade clears the previous version's program files first so no stale libraries are left behind.
Packaging and CI
- The hardware end-of-sale / end-of-support table is now included in the wheel, the single-file
command line, the desktop app folder, the portable zip and the installer. It had shipped in
none of them since the feature was added, so the end-of-support checks on the Compliance page
and in the hardware list found nothing in released builds. A test now pins the package-data
globs and both PyInstaller specs (which share one list in
packaging/bundle.py) to the files on disk, and CI checks the frozen binaries for the data files. - Project metadata: MIT licence file, licence/URL/classifier metadata, and the optional extras
netmap[keyring](secret storage on Linux) andnetmap[test]. - The Linux command-line binary is built on Ubuntu 22.04, so it runs on any distribution with
glibc 2.35 or newer (Ubuntu 22.04+, Debian 12+, RHEL/Rocky/Alma 9+). Command-line release
files carry the version in their name (
netmap-<version>-win-x64.exe,netmap-<version>-linux-x64). - CI: the real-SNMP end-to-end tests fail loudly with the simulator's output when the simulated agents do not start (they had been skipped silently on every run); tests run on Python 3.11 and 3.12; actions are pinned to commit SHAs with Dependabot keeping them and the build tooling current; one build per tag instead of two; only the release job can write to the repository; release notes are taken from this file.
- Tests no longer bind fixed ports, so they run alongside anything else on the machine.
netmap.toml.exampledocuments the[crawl]keys the loader reads (resolve_names,identify,port_scan,os_detect) and which options are command-line only.tools/make_sample.pyregenerates the bundled sample project;tools/refresh_screenshots.pyrefreshes the README screenshots from the app's self-test.
0.9.0 · 2026-09-30
A correctness pass over the parts of the tool that decide where a host sits and what a device is, plus responsiveness at very large inventories.
Topology and identification
- Host-to-switch-port placement: uplinks are recognised by what they are (trunk ports, LAG members and port-channel aggregators, not only ports with an LLDP/CDP neighbour), and a MAC learned by several switches along its path is placed on the access port that carries the fewest addresses - the leaf - instead of one switch picked arbitrarily. Hosts are no longer pinned to trunks behind unmanaged or LLDP-silent switches.
- First-hop redundancy: an HSRP/VRRP virtual address resolves to the active router, so routes whose next hop is the virtual gateway follow through and the real gateway is named.
- Path tracing labels ingress and egress ports correctly when a hop is traversed against the order the link was stored in.
- Device model is parsed from the system description for vendors that leave the standard hardware MIB blank (firewalls, wireless controllers, routers and many access switches), so the Model column is populated on far more real equipment. A model from the hardware MIB is never overwritten.
- An unauthenticated SSH banner read gives the operating system of hosts that offer SSH, with no privileges needed.
- MAC vendor lookup no longer reports registry placeholders as a manufacturer for addresses in shared IEEE blocks.
- Small unprivileged UDP checks confirm DNS and NTP servers, which a TCP scan cannot see, so the DNS / NTP server functions are populated on real scans.
Scanning
- Progress is saved about every five seconds during a crawl instead of after every device, which removed a stall on large networks; the final save still captures everything.
- 32-bit interface counters that wrap between two polls are corrected instead of being reported as zero utilisation.
nmapsubprocesses are always reaped on timeout or cancel.
Desktop app
- The topology graph is cached and rebuilt only when the inventory changes, list filtering and sorting reuse cached text and keys, and findings use the subnet index: a page switch, filter keystroke or selection at tens of thousands of hosts no longer rebuilds everything.
0.8.1 · 2026-09-30
Fixed
- A single transient timeout while reading a device's system group no longer drops a device that had already answered SNMP; partial data is kept.
- A table walk that hits an error part-way through keeps the rows gathered so far instead of returning nothing (a device that returned forty interfaces then errored used to yield zero).
- Web servers running PHP are no longer mistaken for printers; port 3000 alone no longer implies a monitoring server.
- An interface with a 0.0.0.0 mask (tunnels, unnumbered links) no longer creates a catch-all subnet that matched every address.
- Probing every address in a /31 point-to-point range probes both addresses.
- Network devices no longer list their own management interfaces as served "functions".
0.8.0 · 2026-09-30
Added
- Server functions from open ports: a host can fill several roles at once, so they are listed as functions (a Hosts column, a details row, and a Server functions breakdown on the overview) - web, database (named by engine), file, mail, DNS/DHCP/NTP, directory / domain controller, print, virtualization host, containers, message queue, proxy, backup.
- Where the ports are unambiguous the primary role is sharpened (web server, database, mail server, DNS server, domain controller, hypervisor, file server), each with its own icon on the map, the HTML map and the diagram export.
- Client machines are not mistyped: file sharing and remote desktop alone never make a PC a file server, and a host offering no real service stays a plain endpoint.
- Functions can be filtered and queried (
type:database,hosts where functions ~ "PostgreSQL"). - The sample network gained a realistic server fleet to show the classification.
0.7.0 · 2026-09-30
Added
- Broad unauthenticated discovery as part of Identify hosts: WS-Discovery (printers, ONVIF cameras, Windows), IPMI (lights-out controllers) and OT/ICS protocols (Modbus/TCP, BACnet/IP, EtherNet/IP), with vendor and model where the protocol gives them.
- New device types with icons: PLC / controller, building automation, OT / industrial, lights-out (BMC).
- Coverage gaps: every private network the routing tables reference but the scan never reached is flagged as "Subnet not yet scanned".
0.6.0 · 2026-09-30
Added
- Agentless server inspection over read-only SSH (Linux/Unix) and WinRM (Windows): OS, hardware, installed software, running services and active connections.
- Dependency mapping from the collected connections: a Dependencies page and a per-host tab.
- VMware discovery (vCenter/ESXi, read-only) folding hosts and VMs into the map.
- Switch faceplate view, scheduled rescans, a query language over the inventory, a read-only REST API on localhost, and a Preferences dialog.
0.5.0 · 2026-09-30
Added
- Compliance page (management-plane configuration checks), offline hardware end-of-sale / end-of-support lookup, interface health (errors, discards, duplex, utilisation) and PoE.
- Configuration capture over SSH with revision history and diff.
- DHCP lease/scope import; a passive syslog and SNMP trap listener.
0.4.0 · 2026-09-30
Added
- Host identification from many weak signals (NetBIOS, mDNS, SSDP, HTTP/TLS), with the evidence kept and a confidence per host.
- Routed topology: HSRP/VRRP gateways, OSPF/BGP neighbours, spanning-tree root.
- Path tracing (switched and routed) with the path lit up on the map.
0.3.0 · 2026-09-30
Added
- The Windows desktop app: topology map (physical and logical), lists, details, notes, compare with another scan, exports; installer and portable zip built by CI.
- Check a project against an asset list you were given.
- Hardware inventory (chassis, modules, power supplies, transceivers), OS versions, per-port VLANs and LAGs.
0.2.0 · 2026-09-29
Added
- Inventory named subnets directly (targets), offline device typing from the MAC vendor table,
IPAM figures, and a single-file
netmap.exebuilt by CI.
0.1.0 · 2026-09-22
Added
- First release: SNMP/LLDP/CDP crawler with routes, ARP, MAC tables and VLANs, and an interactive topology map.