Documentation

Everything you need to go from an installer to a documented network.

Getting started

SubnetSleuth is a Windows desktop app and a command line (Windows and Linux) that share one project file. This guide takes you from the download to your first map in about fifteen minutes.

1. Install

Download the installer and run it. It installs for your Windows account only, so no administrator rights are needed, and adds a Start menu entry and the .sleuth file type. The portable zip is the same app as a folder: unzip it anywhere (a USB stick, a jump host) and run SubnetSleuth.exe.

Your 14-day trial starts the first time you open it. No account or card is needed.

Optional: install Nmap if you want port scans and deep scans. SubnetSleuth finds it automatically.

2. Look around the sample network

Choose Help ▸ Explore the sample network. It opens a simulated campus (a firewall pair, a core pair, floor and warehouse switches, a server room and about 500 endpoints) so you can try the map, the pages and the exports before pointing SubnetSleuth at anything real.

3. Save a read-only SNMP credential

Open Connections ▸ Connections and credentials (Ctrl+Shift+K), go to Credentials and add an SNMP community (v2c) or an SNMPv3 user. Use a read-only credential: SubnetSleuth never writes, but a read-only credential guarantees it. Test tries it against one device before you rely on it.

A credential can be limited to networks, for example the ranges of one site or one customer: it is then never sent anywhere else, however wide a scan is.

4. Run your first scan

Choose Scan ▸ New scan (Ctrl+R):

  • Address ranges to inventory: the subnets you are responsible for, as CIDR, single addresses or ranges such as 10.20.0.10-60.
  • Start from devices (optional): a core switch or router to follow neighbours outwards from.
  • Never touch: ranges that must not be sent anything at all (OT, medical, partner links).

The dialog shows exactly what will be contacted before you start. Results appear while the scan runs, and Stop keeps everything found so far. Save the project (Ctrl+S) as a .sleuth file.

5. Add what your platforms know

Under Connections, add your firewall manager, cloud dashboard, firewalls, Active Directory, Windows DNS and DHCP servers or vCenter, each with the credential it signs in with, then Pull. Each source lists the read-only access it needs. After a pull, SubnetSleuth offers to scan the subnets the platform serves and poll the devices it manages. See Connections and credentials.

6. Understand, document and share

  • Overview, Network devices, Hosts, Subnets, VLANs and Links list everything found.
  • Topology map draws the physical and logical views; right-click a device for its actions.
  • Needs attention lists what is worth acting on.
  • Select anything and use the Notes tab: owner, site, asset tag, status and notes survive every rescan.
  • File ▸ Export: an Excel workbook, CSV, a draw.io diagram, PDF, PNG, SVG or an interactive HTML map.
  • F5 re-polls everything already known; Tools ▸ Compare with another project shows what changed.

7. Activate your licence

When you buy, you get a licence key straight away. Paste it into Help ▸ Licence. See Licences and activation.