Peter Aleksander Bizjak

new-arp-scan

ARP subnet scanner in Rust for Linux and macOS. Map live hosts on your IPv4 subnet using raw link-layer access.

This tool is under active development. Review the documented platform, permission, and output behavior before relying on it in automation.

Quick start

new-arp-scan interfaces
new-arp-scan monitor [--interface <NAME>] [--timeout-ms <MILLISECONDS>]
new-arp-scan scan [--interface <NAME>] [--host <IPv4>] [--timeout-ms <MILLISECONDS>] [--pacing-ms <MILLISECONDS>] [--attempts <COUNT>] [--bandwidth <BITS_PER_SECOND> | --interval-ms <MILLISECONDS>]

Live scans run on Linux (requires CAP_NET_RAW) and macOS (requires root / BPF access). See documentation for behavior and limits.

Contributor guides (Markdown)

  • Onboarding — build, lint, tests, conventions summary
  • Architecture — modules, unsafe boundaries, packet flow, testing strategy
  • Linux platform — raw sockets, capabilities, namespaces
  • macOS platform — Berkeley Packet Filter, root requirements, validation

Current capabilities

  • List interfaces (on Linux and macOS) that pass the same ARP-scanning filters used by automatic scan selection.
  • Scan an explicit interface, or omit --interface when exactly one usable interface exists.
  • Optionally probe a single strictly interior IPv4 with --host.
  • Configure the post-send receive window, inter-round pacing, and scan round count with millisecond and count flags.
  • Optionally space outbound requests with --bandwidth or --interval-ms. That is a strict send interval, not congestion control; --pacing-ms stays between rounds.
  • Consume the Rust library surface for typed commands, defaults, outcomes, and MAC addresses.