Angry IP Scanner


Angry IP Scanner — Free Download. Network scanning

Angry IP Scanner is a high-speed IP address and port scanner designed for network administrators and technical users. It scans IP ranges and their ports, then returns data such as ping time, hostname, and MAC address. The tool supports extensible data gathering via plugins written in Java. Results can be exported to CSV, TXT, XML, or IP-Port list files. The application runs on Windows, macOS, and Linux without installation, using a multithreaded engine for rapid host discovery and port probing across local or remote networks.

5.0(1 ratings)
File size: 23.8 MB
The latest version of Angry IP Scanner is: 3.10.0
Operating system: Windows, Mac OS, Linux
Languages: English
Price: $0.00 USD (Open Source (GPL-2.0))
  • IP Range Scanning. The core capability accepts a single IP, a list of IPs, or a full subnet in CIDR notation. The scanner iterates through each address, sends ICMP echo requests or TCP probes, and marks hosts as alive or dead. A dedicated thread per address allows simultaneous checking of hundreds of targets without serial delay.
  • Port Scanning. After host discovery, the tool can probe specified TCP ports on each live address. Administrators define port ranges or single ports. The scanner attempts connection establishment and records open, closed, or filtered states. This function identifies running services such as HTTP, SSH, or database listeners on target machines.
  • MAC Address Detection. For devices on the same local subnet, the scanner retrieves the physical hardware address via ARP. This identification method helps map IP addresses to specific network interface cards and manufacturers. MAC vendor lookup is integrated, showing the hardware producer for recognized address prefixes.
  • Hostname Resolution. Each discovered IP address can be resolved to a hostname using DNS or NetBIOS queries. The reverse lookup returns the canonical name registered for that address. This assists administrators in recognizing servers, workstations, or printers without accessing them physically.
  • NetBIOS Information Retrieval. On Windows-based networks, the scanner can extract NetBIOS data including computer name, workgroup or domain membership, and the currently logged-in user account. These details support inventory tasks and security audits by revealing machine roles and active sessions.
  • TTL and Ping Time Measurement. The response time for each host is measured in milliseconds. The Time To Live field from IP packets indicates the number of router hops between the scanning machine and the target. Low TTL values may signal distant hosts, while consistent timings help identify network congestion or latency issues.
  • Web Server Detection. When port 80 or 443 is open, the scanner can verify the presence of an HTTP or HTTPS server. This detection sends a standard request and inspects the response header. Administrators use this to locate unauthorized web services or to inventory legitimate intranet sites.
  • Customizable Openers. Scanned IP addresses can be passed to external applications for further action. The tool allows configuration of custom commands or launchers that receive the IP or hostname as an argument. Common uses include opening SSH clients, RDP sessions, or browser-based management consoles directly from scan results.
  • Favorites Management. Frequently scanned IP ranges and port configurations can be stored as named favorites. This storage allows quick re-runs of routine checks without re-entering addresses or parameters. Administrators maintain separate profiles for different subnets, VLANs, or geographic locations.
  • Result Exporting. Scan outcomes can be saved in multiple formats including CSV, TXT, XML, and IP-Port pair lists. Export files serve as documentation for audits, input for other software tools, or historical records of network state changes. The IP-Port format specifically feeds vulnerability scanners or penetration testing workflows.
  • Plugin Architecture. The functionality of Angry IP Scanner extends through a plugin system. Developers write Java classes that act as fetchers, feeders, or exporters. Fetchers gather additional data per host beyond default fields. Feeders supply target lists from external sources. Exporters define new output formats. This modular design supports specialized scanning needs without modifying the core application.
  • Multithreaded Engine. Each scanned IP address runs in its own thread, enabling parallel processing across large networks. The default configuration uses virtual threads for efficient resource management. Scan speed depends on network bandwidth and target responsiveness, but the architecture eliminates sequential bottlenecks found in single-threaded scanners.
  • Alive Only Display Mode. The results interface can filter out unresponsive hosts automatically. This mode reduces visual clutter during large subnet sweeps where many addresses are unassigned. Administrators see only active devices, improving readability and speeding manual review of discovered assets.
  • SQL Export Security. A specialized exporter produces SQL files for database import. Recent updates added quoting of shell arguments passed to openers and sanitization of SQL generated by the exporter. These protections prevent command injection via malicious DNS responses and SQL injection through crafted IP or hostname data.

Angry IP Scanner began development in 2001 under the name IPSCAN by Anton Keks. The original codebase was written in Java to ensure cross-platform compatibility across Windows, Linux, and macOS. Early versions focused on fast ping sweeps using ICMP echo requests. In 2003 the project was renamed Angry IP Scanner and gained a graphical user interface built with the Standard Widget Toolkit (SWT). The lead developer, Anton Keks, continues to maintain the project from Estonia. Over two decades, the application evolved from a simple ping tool into a modular network reconnaissance platform. The plugin API introduced in version 3.0 allowed third-party developers to add custom data gathering and export capabilities.

Alternatives to Angry IP Scanner:

PortableFix — Free Download. Windows repair

PortableFix

PortableFix is a portable diagnostic and repair utility for Windows 10 and 11 that operates from a USB stick without installation.
Price: Free   Size: 54.4 MB   Version: 1.11.0   OS: Windows
Copper Goose — Free Download. Network fault diagnosis

Copper Goose

Copper Goose Network Monitor is a desktop app for Windows 10 and 11 that continuously watches an internet connection while it is idle, builds a baseline of what normal performance looks like for that specific line, and then issues a plain sentence identifying which piece of equipment is at fault when something departs from that baseline.
Price: $14   Size: 2.5 MB   Version: 3.19.04   OS: Windows
Subnetlens — Free Download. Network scanner

Subnetlens

Subnetlens is a Windows desktop application for local network discovery, device classification, topology mapping, and IT diagnostics.
Price: Free   Size: 118 MB   Version: 1.2.0   OS: Windows
SnmpLens — Free Download. SNMP browser

SnmpLens

SnmpLens is a native desktop application for browsing, querying, and monitoring SNMP-enabled devices across Windows, macOS, and Linux.
Price: Free   Size: 6.14 MB   Version: 1.6.0   OS: Windows, Mac OS, Linux