Angry IP Scanner

angryip.org

Lightweight cross-platform IP and port scanner with CSV/JSON export.

Network Recon & Monitoring Free & Open Source GUI Learning Cross-platform

Cyber Kill Chain & Defender Lifecycle

Attacker — Kill Chain
1 Reconnaissance
2 Weaponization
3 Delivery
4 Exploitation
5 Installation
6 Command & Control
7 Actions on Objectives
Defender — IR Lifecycle
8 Detection / Monitoring
9 Containment & Eradication
10 Post-incident Forensics

Description

Angry IP Scanner is a fast, simple cross-platform scanner written in Java. It is not as deep as Nmap, but it is excellent for a quick sweep on a flat network when you just need to know "what is alive on this /24 and on which ports?".

Strengths:

  • Multithreaded — scans a Class C in seconds.
  • Plugin-extensible (NetBIOS info, MAC vendor lookup, HTTP titles).
  • Exports CSV, TXT, XML, IP-Port list — easy to feed into a spreadsheet or a SIEM.

Use cases

  • Quick LAN sweep at the start of an incident
  • Helpdesk-level inventory checks
  • Initial port triage before deeper Nmap follow-up