Command line
The same scanner and the same project file, for scripted and scheduled runs: subnetsleuth.exe on Windows
(also subnetsleuth-cli.exe in the installed app's folder) and subnetsleuth on Linux. Saved credentials,
connections and the licence are shared with the desktop app on the same computer. subnetsleuth --help and
subnetsleuth COMMAND --help list every option.
Credentials
A secret is never typed on the command line: it is asked for (no echo) or read from an environment variable.
subnetsleuth credentials add snmp-v3 --label campus-ro --set user=netops --set auth=SHA256 --set priv=AES256 \
--secret auth_key --secret priv_key
subnetsleuth credentials add snmp-community --label legacy-ro --secret community=env:LEGACY_RO --networks 10.40.0.0/16
subnetsleuth credentials test campus-ro 10.20.0.1
subnetsleuth credentials list
Scans
# Inventory the ranges you are responsible for, and nothing else
subnetsleuth crawl --target 10.20.0.0/24 --target 10.30.0.0/24 --credential campus-ro \
--dns --out site.sleuth --xlsx site.xlsx --drawio site.drawio
# Follow neighbours outwards from a core device, bounded by a scope
subnetsleuth crawl --seed 10.10.0.1 --scope 10.10.0.0/16 --saved-credentials --out site.sleuth
# Identify hosts and scan their ports (needs Nmap for --port-scan)
subnetsleuth crawl --target 10.20.0.0/24 --credential campus-ro --identify --port-scan --out site.sleuth
# Later: re-poll everything already known; notes and layout are kept
subnetsleuth crawl --resume --refresh --seed 10.10.0.1 --scope 10.10.0.0/16 --credential campus-ro --out site.sleuth
# Every few hours, unattended
subnetsleuth crawl --resume --refresh --seed 10.10.0.1 --scope 10.10.0.0/16 --credential campus-ro \
--out site.sleuth --repeat 21600
Connections and pulls
subnetsleuth connections sources
subnetsleuth credentials add token --label meraki-key --secret token=env:MERAKI_KEY
subnetsleuth connections add meraki --label "Acme Meraki" --credential meraki-key
subnetsleuth connections test "Acme Meraki"
subnetsleuth pull -m site.sleuth --all --scan
Outputs
subnetsleuth render -m site.sleuth --html map.html --xlsx site.xlsx --csv site- --drawio site.drawio
subnetsleuth diff last-month.sleuth site.sleuth
subnetsleuth show -m site.sleuth # a text summary
subnetsleuth serve -m site.sleuth # read-only REST API on this computer, with the query language:
curl "http://127.0.0.1:8088/query?q=hosts%20where%20os%20~%20windows%20and%20port%20%3D%203389"
Licence
subnetsleuth license status
subnetsleuth license activate subnetsleuth-pro-lic_0123456789abcdef.lic
subnetsleuth license remove
Asking AI
subnetsleuth ai types
subnetsleuth ai add bedrock --label "Claude on Bedrock" -S aws_region=us-east-1 -S aws_profile=corp-ai --default
subnetsleuth ask -m site.sleuth --preset overview
subnetsleuth ask -m site.sleuth --handoff chat --out ~/Documents "What is on VLAN 30?"
subnetsleuth mcp install # SubnetSleuth as a connector in Claude Desktop and Cowork