Subnetlens


Subnetlens — Free Download. Network scanner

Subnetlens is a Windows desktop application for local network discovery, device classification, topology mapping, and IT diagnostics. It scans subnets, identifies devices through a 1,451-pattern database, builds an interactive map, and provides 26 built-in tools including ping, traceroute, DNS lookup, port scan, WHOIS, GeoIP, TLS checks, and HTTP header inspection. Monitoring features track device appearance, port changes, and hostname changes in real time.

5.0(1 ratings)
File size: 118 MB
The latest version of Subnetlens is: 1.2.0
Operating system: Windows
Languages: English
Price: $0.00 USD (Freemium product ($79 or free version))
  • Subnet scanning. Subnetlens performs CIDR and range scanning through a seven-step pipeline. Users can save scan profiles for repeated use. The scanner reads ARP tables, sends ping requests, resolves hostnames, examines open ports, and gathers service banners. Scans can run quickly with ARP and ping only, or in full mode with enrichment across all steps. The free tier supports one saved profile and a single subnet, while Pro allows multiple profiles for different networks.
  • Interactive network map. The application builds a visual topology of the local network showing how devices relate to each other. When SNMP is enabled, the map displays physical connections derived from switch port-to-MAC mapping. Devices appear as nodes with labels, and links between them represent observed relationships. The map updates after scans and supports zooming and selection of individual devices for detail views.
  • Device classifier. Every discovered device receives a type such as router, switch, server, workstation, printer, phone, camera, NAS, or IoT. Classification uses more than fourteen signals: open ports, MAC vendor, hostname patterns, HTTP and SSH banners, mDNS and SSDP services, DHCP fingerprints, TTL values, and port counts. The bundled database contains 1,451 hostname patterns across thirteen categories. Each device shows the top three reasons for its assigned type.
  • Network Radar. Radar presents a real-time event timeline and a tactical-radar canvas. It detects new devices, disappeared devices, port changes, and hostname changes as they happen. Anomaly detection highlights noteworthy events without manual review. A magnifying-glass cursor lens allows precise selection of small elements. Radar is part of the Pro tier and works together with Live Mode.
  • Live Mode. A REC indicator in the header toggles continuous mDNS and SSDP listening. This captures every device the moment it broadcasts, including between scheduled scans. Devices pulse with a soft halo when they send network announcements. Live Mode complements periodic scanning by filling the gaps between scan cycles and revealing transient or intermittently active hosts.
  • Per-device port history. Each scan records which ports opened or closed on every device. A timeline view per device shows changes over time with NEW since baseline badges when a port appears that was not present before. This provides security-grade visibility into service changes. Port history is available from the device details panel in the Explorer section and is part of the Pro tier.
  • Port Watch. Users define extra ports that matter, either on every device or on a single device. After each scan, each watched port is reported as open, closed, no answer, or not scanned yet, along with the last check time and the last change time. A port outside a scan is never labeled closed. Every open or close event also appears in Radar and in the port history.
  • Device insights and deep scans. Each device receives a risk score from 0 to 100. A one-click deep dive examines TLS configuration, HTTP headers, SSH exposure and banners, and matches banner patterns against eight known CVE signatures. The tool does not perform credential authentication or vulnerability verification. Results export to CSV or JSON for review and reporting. This feature lives on the Risk page and belongs to the Pro tier.
  • Control Panel and Explorer. Selecting a device reveals context-aware actions such as RDP, SSH, CMD, camera streams, SNMP reboots, database connection strings, and IPP test-page printing. An in-app credential modal with Vault auto-fill supplies login data. Clicking any tile on the Explorer card opens a single-device workshop with Files, Ports, Web, Risk, and Notes sections. The Control Panel is part of the Pro tier.
  • Credential Vault. The vault stores credentials locally using AES-256-GCM encryption with PBKDF2 at 600,000 iterations. It imports from KeePass, 1Password, LastPass, and Bitwarden exports. Stored credentials auto-fill the Control Panel shell launchers and RDP or SSH context actions. No cloud synchronization occurs. The Vault is a Pro feature.
  • Scheduled scanning. Schedules use cron expressions or interval presets. Each schedule runs either a quick scan with ARP and ping or a full seven-step scan. Webhook integrations deliver results to Slack, Discord, Microsoft Teams, or any custom URL with SSRF hardening. Smart retries handle transient failures, and schedules auto-disable after repeated errors.
  • SNMP topology and Sentinel. With SNMP enabled, the application maps switch ports to MAC addresses and draws enhanced topology edges representing physical connections. It collects interface statistics and supports SNMPv3 and a trap receiver. Sentinel is a background poller that watches the network while the user works, running from the system tray and feeding events into Radar.
  • Prometheus exporter. A built-in metrics HTTP endpoint exposes device counts, port statistics, and scan durations. It integrates with existing Grafana and Prometheus stacks. Three lines in prometheus.yml are sufficient to begin scraping. The exporter is configured from the Prometheus section in Settings and is part of the Pro tier.
  • Command Palette. Pressing Ctrl+K from anywhere opens a fuzzy-search palette. Users search every device by IP, hostname, or vendor, jump to any page, and run common actions using only the keyboard. The palette follows the pattern popularized by code editors and provides fast navigation without mouse interaction.
  • IT Toolkit. The toolkit contains 26 diagnostic tools, of which 8 are free and 18 require Pro. Tools include Ping, Traceroute, MTR, Port Scan, DNS Lookup, WHOIS, GeoIP, TLS Check, HTTP Headers, Cert Decoder, MAC Lookup, Subnet Calculator, Hash Calculator, Bandwidth testing, Format and Encode utilities, Cron Tester, SMB Browser, and others. All tools produce streaming output and support favorites.
  • IP address management. The IPAM section tracks address usage across a subnet, distinguishing online, offline, reserved, DHCP pool, static, and free addresses. It gives administrators a structured view of allocation and helps prevent conflicts. IPAM is included in the Pro tier and integrates with scan results and the network map.
  • Reporting and export. Pro users generate HTML reports containing scan results, device inventories, risk findings, and topology information. Data also exports to CSV and JSON for use in other systems. Reports are suitable for documentation, audits, and stakeholder communication. The reporting module is part of the Pro tier.
  • Embedded terminal. A terminal panel inside the application allows command execution without switching to a separate window. It supports context from the selected device and works with the credential vault for authenticated sessions. The terminal is a Pro feature and complements the shell launcher actions in the Control Panel.

Subnetlens is developed by HELIOSOFT LTD, a company registered in the United Kingdom. The product reached version 1.0.0 as a full release after a public beta programme that shaped its feature set. Development continues with updates included for one year with each Pro license. The application is written in C# using the .NET framework and targets Windows 10 and Windows 11 on 64-bit systems. The installer is code-signed through Azure Trusted Signing, and the download page publishes a SHA-256 checksum for verification. The developers position the tool for IT administrators, managed service providers, small businesses, and home lab users who need local network visibility without cloud dependencies or recurring subscription costs.

Alternatives to Subnetlens:

Copper Goose — Free Download. Network fault diagnosis

Copper Goose

Copper Goose Network Monitor is a desktop app for Windows 10 and 11 that continuously watches an internet connection while it is idle, builds a baseline of what normal performance looks like for that specific line, and then issues a plain sentence identifying which piece of equipment is at fault when something departs from that baseline.
Price: $14   Size: 2.5 MB   Version: 3.19.04   OS: Windows
SnmpLens — Free Download. SNMP browser

SnmpLens

SnmpLens is a native desktop application for browsing, querying, and monitoring SNMP-enabled devices across Windows, macOS, and Linux.
Price: Free   Size: 6.14 MB   Version: 1.6.0   OS: Windows, Mac OS, Linux
Veltrea Syslog Server — Free Download. Syslog receiver

Veltrea Syslog Server

Veltrea Syslog Server is a high-performance network log receiver built to capture syslog messages over UDP and display them in a live, scrollable console.
Price: Free   Size: 3.52 MB   Version: 0.4.0   OS: Windows, Mac OS, Linux
Angry IP Scanner — Free Download. Network scanning

Angry IP Scanner

Angry IP Scanner is a high-speed IP address and port scanner designed for network administrators and technical users.
Price: Free   Size: 23.8 MB   Version: 3.10.0   OS: Windows, Mac OS, Linux