Peter Aleksander Bizjak
new-arp-scan
ARP subnet scanner in Rust for Linux and macOS. Map live hosts on your IPv4 subnet using raw link-layer access.
This tool is under active development. Review the documented platform, permission, and output behavior before relying on it in automation.
Quick start
new-arp-scan interfaces
new-arp-scan monitor [--interface <NAME>] [--timeout-ms <MILLISECONDS>]
new-arp-scan scan [--interface <NAME>] [--host <IPv4>] [--timeout-ms <MILLISECONDS>] [--pacing-ms <MILLISECONDS>] [--attempts <COUNT>] [--bandwidth <BITS_PER_SECOND> | --interval-ms <MILLISECONDS>]
Live scans run on Linux (requires CAP_NET_RAW)
and macOS (requires root / BPF access). See
documentation for behavior and limits.
Contributor guides (Markdown)
- Onboarding — build, lint, tests, conventions summary
- Architecture — modules, unsafe boundaries, packet flow, testing strategy
- Linux platform — raw sockets, capabilities, namespaces
- macOS platform — Berkeley Packet Filter, root requirements, validation
Current capabilities
- List interfaces (on Linux and macOS) that pass the same ARP-scanning filters used by automatic scan selection.
- Scan an explicit interface, or omit --interface when exactly one usable interface exists.
- Optionally probe a single strictly interior IPv4 with --host.
- Configure the post-send receive window, inter-round pacing, and scan round count with millisecond and count flags.
- Optionally space outbound requests with --bandwidth or --interval-ms. That is a strict send interval, not congestion control; --pacing-ms stays between rounds.
- Consume the Rust library surface for typed commands, defaults, outcomes, and MAC addresses.