Know what is on your network.Without telling anyone else.
Loomscope finds what is on your network, works out how it fits together, and tells you which parts are exposed. It runs on your own infrastructure — no SaaS tier, no phone-home, and an air-gapped install is a supported path rather than an afterthought.
Early software. Feature status says what works, what is partial and what is not implemented — without rounding anything up.
git clone https://github.com/bendaamerahmed/loomscope.git
cd loomscope && cp .env.example .env
docker compose -f infra/docker-compose.yml up -d postgres serverThen enrol a daemon, add a CIDR, and hosts appear within about thirty seconds.
Nothing leaves
No telemetry, no licence check, no update ping.
Two containers and a database
No Redis, no broker, no websocket layer to operate.
Daemons dial out
Nothing ever connects towards a scanner. NAT and DMZs are ordinary.
Gaps are written down
The documentation states what does not work as plainly as what does.
An inventory, a map, and an honest account of what is exposed
Every claim below has a page behind it explaining how it is produced and where it stops being reliable.
Discovery that does not guess
ICMP, ARP, TCP and UDP in both address families, plus SNMP v1/v2c/v3 for the devices that only speak that. Hardware vendors resolved from the MAC, which is often the only thing a printer or a badge reader will tell you. Nothing to install on the machines you are discovering.
Read moreA scanner where you already have a machine
Native binaries for Linux, Windows and macOS. MAC addresses without raw sockets, Npcap or Administrator — the daemon reads the operating system's own neighbour cache. Each one reports what it can actually see there, so a daemon that can do less never looks like one that can do more.
Read moreServices, not open ports
Grafana is identified by /api/health returning grafana — not by port 3000 being open. Every match carries a confidence score, and it propagates.
Read moreFour topology views
What is plugged into what, how traffic routes, what runs inside what, and what talks to what — four views over one inventory. Move a node by hand and your layout survives the next regeneration.
Read moreVulnerabilities you can weigh
OSV and NVD, matched against discovered versions. The list tells you whether a finding came from a structured CPE or from a banner, because those are not the same claim.
Read moreChange tracking
Daily snapshots, a diff between any two of them, and a PDF attestation of the inventory on a date. The fastest answer to what changed since Friday.
Read moreCloud, correlated
AWS and Kubernetes inventoried from the control plane — so daemon hosts hold no cloud credentials — and matched against scanned hosts rather than listed beside them.
Read moreIdentity that actually revokes
OpenID Connect with group-to-role mapping, and SCIM 2.0 where deprovisioning ends the sessions somebody already holds rather than only their next sign-in.
Read moreAlerting without a second subsystem
Eight event types to Slack, Teams, PagerDuty, Jira or a signed webhook. Deduplicated by the emitter, so a certificate found hourly announces once.
Read moreDeliberately small, because you are the one on call
A Next.js control plane, one or many Go daemons, and PostgreSQL as the single source of truth. Realtime updates ride Server-Sent Events over LISTEN/NOTIFY, so there is no broker, no second delivery path, and nothing that needs a proxy exemption to survive a corporate middlebox.
- Daemons poll outbound — nothing connects towards them
- Cloud discovery runs in the control plane, never on a scanner
- Row-level security is the tenant boundary, not a WHERE clause
- Migrations are forward-only SQL, linted, expand-and-contract
The review you can hand to a CISO
Loomscope holds a map of your network, a list of your weaknesses and credentials for your infrastructure. The design assumes a daemon host may be compromised, a database may be exfiltrated, and an operator may forget a filter.
The full security model — including what is left to you- Linux capabilities on the scanner
- All dropped but NET_RAW
- Where the scanner runs
- Linux, Windows, macOS — natively
- Data sent to third parties
- None — nmap's external scripts excluded
- Privileged containers
- None, ever
- Inbound connections to a daemon
- None — it polls outbound
- Cloud credentials on a daemon host
- None
- Tenant isolation
- PostgreSQL RLS, FORCEd
- Credentials at rest
- AEAD, key held outside the database
- Telemetry, licence checks, update pings
- None
- Licence
- AGPL-3.0-only
Being explicit about this saves an evaluation
Not a vulnerability scanner
It matches advisories against the versions it identified. No exploitation, no authenticated checks, no intrusive probes.
Not a monitoring system
It records what exists and what changed — not latency, saturation or uptime. It will not page you because a disk filled.
Not agent-based
Nothing is installed on discovered hosts. A host that answers nothing at all will not be found by active scanning, and the docs say so.
Not SaaS with a self-hosted option
Self-hosting is the only shape. There is no hosted control plane to fall back to, and no account to create.
Written for a specific reader, and kept in the repository
Every page on this site is built from the Markdown in docs/, so the version you read here and the version in the repository cannot disagree.
Installation
Deploying it somewhere people depend on.
Using Loomscope
Getting answers out of it.
Identity and access
Who can do what, and how a directory drives it.
Reference
The precise version.
Operations
Running it for the second year, not the first week.
Ten minutes to a scanned network
Docker and Docker Compose, a range you are authorised to scan, and four generated secrets. The quick start says where it cuts a corner, and what to read before anyone depends on it.