Skip to content
self-hosted · AGPL-3.0 · air-gap compatible

Know what is on your network.Without telling anyone else.

Loomscope finds what is on your network, works out how it fits together, and tells you which parts are exposed. It runs on your own infrastructure — no SaaS tier, no phone-home, and an air-gapped install is a supported path rather than an afterthought.

Early software. Feature status says what works, what is partial and what is not implemented — without rounding anything up.

Three commands to a running control plane
bash
git clone https://github.com/bendaamerahmed/loomscope.git
cd loomscope && cp .env.example .env

docker compose -f infra/docker-compose.yml up -d postgres server

Then enrol a daemon, add a CIDR, and hosts appear within about thirty seconds.

Nothing leaves

No telemetry, no licence check, no update ping.

Two containers and a database

No Redis, no broker, no websocket layer to operate.

Daemons dial out

Nothing ever connects towards a scanner. NAT and DMZs are ordinary.

Gaps are written down

The documentation states what does not work as plainly as what does.

What it does

An inventory, a map, and an honest account of what is exposed

Every claim below has a page behind it explaining how it is produced and where it stops being reliable.

Discovery that does not guess

ICMP, ARP, TCP and UDP in both address families, plus SNMP v1/v2c/v3 for the devices that only speak that. Hardware vendors resolved from the MAC, which is often the only thing a printer or a badge reader will tell you. Nothing to install on the machines you are discovering.

Read more

A scanner where you already have a machine

Native binaries for Linux, Windows and macOS. MAC addresses without raw sockets, Npcap or Administrator — the daemon reads the operating system's own neighbour cache. Each one reports what it can actually see there, so a daemon that can do less never looks like one that can do more.

Read more

Services, not open ports

Grafana is identified by /api/health returning grafana — not by port 3000 being open. Every match carries a confidence score, and it propagates.

Read more

Four topology views

What is plugged into what, how traffic routes, what runs inside what, and what talks to what — four views over one inventory. Move a node by hand and your layout survives the next regeneration.

Read more

Vulnerabilities you can weigh

OSV and NVD, matched against discovered versions. The list tells you whether a finding came from a structured CPE or from a banner, because those are not the same claim.

Read more

Change tracking

Daily snapshots, a diff between any two of them, and a PDF attestation of the inventory on a date. The fastest answer to what changed since Friday.

Read more

Cloud, correlated

AWS and Kubernetes inventoried from the control plane — so daemon hosts hold no cloud credentials — and matched against scanned hosts rather than listed beside them.

Read more

Identity that actually revokes

OpenID Connect with group-to-role mapping, and SCIM 2.0 where deprovisioning ends the sessions somebody already holds rather than only their next sign-in.

Read more

Alerting without a second subsystem

Eight event types to Slack, Teams, PagerDuty, Jira or a signed webhook. Deduplicated by the emitter, so a certificate found hourly announces once.

Read more
Architecture

Deliberately small, because you are the one on call

A Next.js control plane, one or many Go daemons, and PostgreSQL as the single source of truth. Realtime updates ride Server-Sent Events over LISTEN/NOTIFY, so there is no broker, no second delivery path, and nothing that needs a proxy exemption to survive a corporate middlebox.

  • Daemons poll outbound — nothing connects towards them
  • Cloud discovery runs in the control plane, never on a scanner
  • Row-level security is the tenant boundary, not a WHERE clause
  • Migrations are forward-only SQL, linted, expand-and-contract
How it fits together
Go daemon(s)ICMP · ARP · TCP · SNMPControl planeUI · REST · cloud syncJob workerscans · CVE · snapshotsPostgreSQL 17row-level security, FORCEDREST, outbound onlyregister · poll · observeSQL · LISTEN/NOTIFYadvisory locks
Security posture

The review you can hand to a CISO

Loomscope holds a map of your network, a list of your weaknesses and credentials for your infrastructure. The design assumes a daemon host may be compromised, a database may be exfiltrated, and an operator may forget a filter.

The full security model — including what is left to you
Linux capabilities on the scanner
All dropped but NET_RAW
Where the scanner runs
Linux, Windows, macOS — natively
Data sent to third parties
None — nmap's external scripts excluded
Privileged containers
None, ever
Inbound connections to a daemon
None — it polls outbound
Cloud credentials on a daemon host
None
Tenant isolation
PostgreSQL RLS, FORCEd
Credentials at rest
AEAD, key held outside the database
Telemetry, licence checks, update pings
None
Licence
AGPL-3.0-only
What it is not

Being explicit about this saves an evaluation

Not a vulnerability scanner

It matches advisories against the versions it identified. No exploitation, no authenticated checks, no intrusive probes.

Not a monitoring system

It records what exists and what changed — not latency, saturation or uptime. It will not page you because a disk filled.

Not agent-based

Nothing is installed on discovered hosts. A host that answers nothing at all will not be found by active scanning, and the docs say so.

Not SaaS with a self-hosted option

Self-hosting is the only shape. There is no hosted control plane to fall back to, and no account to create.

Documentation

Written for a specific reader, and kept in the repository

Every page on this site is built from the Markdown in docs/, so the version you read here and the version in the repository cannot disagree.

Ten minutes to a scanned network

Docker and Docker Compose, a range you are authorised to scan, and four generated secrets. The quick start says where it cuts a corner, and what to read before anyone depends on it.