Network infrastructure pentesting with built-in intelligence. Drop it on the jump box, point it at the target range, and get a zoomable topology map, rogue gateway alerts, VLAN hop chains, and a professional HTML report — one static binary, zero dependencies.
Built by a practitioner who thinks like an attacker. Every feature maps to a real engagement task — not a checkbox on a marketing slide.
Hosts auto-populate from scan output. Subnet group boxes, spoke lines to gateway nodes, colour-coded severity borders. Scroll to zoom (0.15×–4×), middle-drag to pan, left-drag nodes to rearrange. Layout is saved between sessions and exported to your HTML report as an embedded SVG.
The cleaning lady plugged in a MikroTik with a static route that bypasses your IDS. IPS finds it. Active /24 ping sweep (not just ARP cache), multi-path traceroute asymmetry detection, management port fingerprinting across 30+ vendors — pfSense, FortiGate, Palo Alto, Huawei, D-Link, TP-Link, Alcatel-Lucent and more. Rogue devices get a red diamond on the topology map and a [!!] alert in the log.
Passive VLAN ID sniff via tshark (auto-detects tags in 10 seconds), CDP/LLDP neighbor capture, and automated 802.1Q double-tag hopping — creates sub-interfaces, pings each VLAN, reports which are reachable. All in a single template, no manual setup.
Configure up to three seed networks (default: 10.0.0.0/24, 172.16.0.0/24, 192.168.0.0/24). Worker threads increment through every /24 in each class and ping-sweep it. Discovered hosts appear on the topology map in real time. Guided by traceroute so probing starts at the networks actually reachable through detected gateways.
Every finding is tagged to the corresponding ATT&CK technique (T1046, T1599, T1016, T1040 …). Severity-ranked, timestamped, exportable. The HTML report includes an executive scorecard, per-finding evidence blocks, and the embedded topology SVG — client-ready from a single session.
One-click execution for Nmap host discovery, ARP sweep, VLAN sniff, CDP/LLDP, gateway routing map, traceroute multi-path, routing protocol detector (OSPF/EIGRP/RIP/BGP/HSRP), static route audit, SSL/TLS cipher audit, Heartbleed, SMBv1, EternalBlue, and gateway device fingerprint. All parameterised with your target and output directory.
Static routes bypass sensors. A device plugged in by anyone — not just the attacker — can route traffic around your IDS, firewall, and DLP without a single alarm. IPS finds them.
ip route show reveals the actual default gateway and any suspicious via entries pointing to unknown IPs. Non-default static routes that route to IPs not in the ARP cache are flagged immediately as potential rogue paths.
Traceroute to three separate destinations (8.8.8.8, 1.1.1.1, 9.9.9.9). If hop-1 differs between paths — asymmetric routing detected. Every hop-1 IP that isn't the default gateway gets flagged as suspicious and added to the probe list.
Full /24 ping sweep of the local subnet (derived from the default gateway's IP) catches devices that never appear in the ARP cache because they haven't been talked to recently. This is how hidden pfSense boxes at .252 get found when .254 is the declared default gateway.
Each candidate device is scanned for management ports (22, 80, 443, 8080, 8443, 8291, 8728, BGP/179…) with nmap + banner grabs. The combined output is matched against 30+ vendor signatures. Device type badge, traceroute hop number, and raw banner excerpt shown in the discovery panel.
Interactive GUI for engagements where you're watching the map build in real time. Headless CLI for scripted pipelines and jump boxes with no display.
Capabilities the enterprise scanners don't ship.
| Capability | IPS -NA- |
Nessus Pro ~$3,900/yr |
OpenVAS Free |
Nmap Free |
Metasploit Pro $15,000/yr |
|---|---|---|---|---|---|
| Rogue gateway detection (active sweep) | ✓ | ✗ | ✗ | ✗ | ✗ |
| Multi-path traceroute asymmetry alert | ✓ | ✗ | ✗ | ~ | ✗ |
| 30+ vendor fingerprints (pfSense to Huawei) | ✓ | ~ | ~ | ~ | ~ |
| 802.1Q VLAN hop automation | ✓ | ✗ | ✗ | ✗ | ~ |
| Beyond-gateway threaded subnet probe | ✓ | ✗ | ✗ | ✗ | ✗ |
| Zoomable live topology map | ✓ | ✗ | ✗ | ✗ | ✗ |
| HTML report with embedded topology SVG | ✓ | ✓ | ~ | ✗ | ✓ |
| MITRE ATT&CK mapped findings | ✓ | ~ | ✗ | ✗ | ~ |
| Debian/Kali native · single binary | ✓ | ✗ | ✗ | ✓ | ✗ |
✓ Full · ~ Partial · ✗ Not available · Pricing from public sources, 2026
Online validation on every launch. Machine-fingerprint locked. No seat sharing.
Prices in EUR excluding VAT. Invoice available via portal. Authorised security testing only.
No credit card. Instant key. You sign — you own the liability.