Introduction
What Loomscope is, what it is not, who it is for
Edit this pageLoomscope finds what is on your network, works out how it fits together, and tells you which parts are exposed. It runs on your own infrastructure — there is no SaaS tier, no telemetry and no phone-home, and an air-gapped install is a supported path rather than an afterthought.
What it does
Loomscope covers the loop between what do we have, how is it connected and what is wrong with it:
- Discovery. ICMP, ARP, TCP and UDP sweeps in both address families, plus SNMP v1/v2c/v3 for the devices that will only talk that way, and NetFlow, IPFIX and sFlow for traffic that active scanning cannot see.
- Service identification. A port being open is not a service. Loomscope matches signatures — a port, an endpoint, an expected response — and records how confident the match is, so you can tell a certainty from a guess.
- Topology. Four generated views over the same inventory: what is plugged into what, how traffic routes, what runs inside what, and what talks to what.
- Vulnerabilities. Discovered services are matched against OSV and NVD, with an offline mirror for installs that have no internet access.
- Certificates. Every TLS handshake the daemon performs is recorded, so "what expires next month" and "what is still self-signed" are queries rather than a spreadsheet.
- Change tracking. Daily snapshots, diffs between any two of them, and a PDF attestation of the inventory on a given date.
What it is not
Being explicit about this saves an evaluation.
- Not a vulnerability scanner. Loomscope matches advisories against the versions it identified. It does not exploit, authenticate into hosts, or perform intrusive checks.
- Not a monitoring system. It records what exists and what changed, not latency, saturation or uptime. It will not page you because a disk filled.
- Not agent-based. Nothing is installed on discovered hosts. The daemon sits on the network and looks at it from the outside, which is why a host that answers nothing at all will not be found by active scanning.
- Not a SaaS product with a self-hosted option. Self-hosting is the only shape. There is no hosted control plane to fall back to.
Who it is for
Teams that need an accurate inventory and cannot send their topology to a third party: regulated environments, air-gapped sites, service providers holding several clients in one deployment, and anyone who would simply rather not.
The permission model assumes more than one person: five organisation roles, per-site overrides that can raise a role but never lower it, an audit log covering every privileged action, and OpenID Connect single sign-on with SCIM provisioning for directories that own the user list.
Status
Loomscope is early. It is usable, covered by CI, and released under AGPL-3.0 — but interfaces may still change, and a few areas are deliberately incomplete. The feature status table states what works, what is partial and what is not implemented, without rounding anything up.
Where to go next
- Quick start — a working install in about ten minutes.
- Core concepts — the four ideas the whole interface is built on.
- Architecture — what the components are, and why there are so few of them.