ARP-SCAN(1) General Commands Manual ARP-SCAN(1) (NAME) arp-scan - ARP (SYNOPSIS) arp-scan [] [...] --file --localnet . IPv4 . CIDR (10.0.0.0/24) ( /Broadcast) (10.0.0.1-10.0.0.10) network:mask (10.0.0.0:255.255.255.0) . (DESCRIPTION) arp-scan ARP . --interface . arp-scan (up) ( loopback) . arp-scan (raw sockets) : POSIX.1e libcap: arp-scan (capabilities aware). CAP_NET_RAW . setcap cap_net_raw+p /path/to/arp-scan CAP_NET_RAW arp-scan . SUID root arp-scan CAP_NET_RAW root . BSD macOS: / /dev/bpf* . : root SUID root . ARP (route) . ARP IPv4 IP arp-scan IPv4 . ARP . . --retry . (packet loss) . arp-scan --bandwidth . . (broadcast) . --interval . ( --retry=1) : time = n x i + t + o n i ( --interval --bandwidth) t ( --timeout) o /MAC . ( ) --quiet . (timeout) . ARP --arpXXX : +-------------------------------------------------------------------+ | ARP | +============+=============+=============+==========================+ |Field | Bits | Option | Default | +============+=============+=============+==========================+ |ar$hrd | 16 | --arphrd | 1 (ARPHRD_ETHER) | |ar$pro | 16 | --arppro | 0x0800 | |ar$hln | 8 | --arphln | 6 (ETH_ALEN) | |ar$pln | 8 | --arppln | 4 (IPv4) | |ar$op | 16 | --arpop | 1 (ARPOP_REQUEST) | |ar$sha | 48 | --arpsha | interface h/w address | |ar$spa | 32 | --arpspa | interface IPv4 address | |ar$tha | 48 | --arptha | 00:00:00:00:00:00 | |ar$tpa | 32 | None | target host IPv4 address | +------------+-------------+-------------+--------------------------+ --arpspa IPv4 ARP ARP . arp-scan IPv4 . : ar$spa IP ARP (address clash) . : +---------------------------------------------------------------+ | | +===============+=============+=============+===================+ |Field | Bits | Option | Default | +===============+=============+=============+===================+ |Dest Address | 48 | --destaddr | ff:ff:ff:ff:ff:ff | |Source Address | 48 | --srcaddr | interface address | |Protocol Type | 16 | --prototype | 0x0806 (ARP) | +---------------+-------------+-------------+-------------------+ --destaddr . ARP : < IPv4> < MAC> < > IPv4 Address IP MAC Address Vendor Details . (Tab) . --format . . ieee-oui.txt mac-vendor.txt . ieee- oui.txt MA-L (OUI) MA-M MA-S (OUI36) IAB IEEE . mac-vendor.txt MAC . get-oui ieee-oui.txt IEEE . IPv4 ARP . arp-scan IPv4 . (OPTIONS) / . : (Character string). 0x 2048 0x800. . MAC 01:23:45:67:89:ab 01-23-45-67-89-ab ( ). IPv4 10.0.0.1 0x ( ). - . (General Options) --help or -h . --verbose or -v . . =. --version or -V . libpcap POSIX.1e . --interface= or -I . arp-scan (up) ( loopback) . (Host Selection) --file= or -f . . (stdin) "-" . --localnet or -l . ( /Broadcast) . --file . --interface . MAC/ (MAC/Vendor Mapping Files) --ouifile= or -O IEEE . ieee-oui.txt . /usr/share/arp-scan/ieee-oui.txt . --macfile= or -m . mac-vendor.txt . /etc/arp-scan/mac-vendor.txt . (Output Format Control) --quiet or -q . IP MAC . . --quiet ${ip} ${mac} --format . --plain or -x . . . --ignoredups or -g . (DUP: n) n . --rtt or -D (RTT). . ${rtt} --format . --format= or -F . . "${field[;width]}" . width . ( ) : IP IPv4 (dotted quad) Name --resolve MAC MAC xx:xx:xx:xx:xx:xx HdrMAC Vendor Padding ARP Framing Ethernet_II VLAN 802.1Q VLAN Proto ARP 0x0800 DUP (>1) RTT --rtt --quiet ${ip} ${mac} . . "\" (escape) : \n (newline) \r (carriage return) \t (tab) \ --format ' ' . : --format='${ip}\t${mac}\t${vendor}' (Host List Randomisation) --random or -R . --randomseed= . --random . (Output Timing and Retry) --retry= or -r =. --backoff= or -b (backoff factor) =.. (timeout) . --timeout= or -t =. . --backoff . --interval= or -i . . --bandwidth . "u" . --bandwidth= or -B =. . K M ( ). --interval --bandwidth . DNS (DNS Resolution) --numeric or -N IP . . --resolve or -d . IPv4 . ${name} --format . ARP (Output ARP Packet) --arpsha= or -u MAC ARP. ar$sha --srcaddr . . --arptha= or -w MAC ARP. ar$tha . ARP . --arphrd= or -H ARP =1. ar$hrd . 1 (ARPHRD_ETHER) . 6 (ARPHRD_IEEE802) . --arppro= or -p ARP =0x0800. ar$pro . 0x0800 (IPv4) . --arphln= or -a =6. ar$hln . ar$sha ar$tha ar$hln . --arppln= or -P =4. ar$pln . ar$spa ar$tpa ar$pln . --arpop= or -o ARP =1. ar$op . 1 (ARPOP_REQUEST) . --arpspa= or -s IPv4 . "dest" . . ar$spa . . ar$spa IP (address clash) . (Output Ethernet Header) --srcaddr= or -S MAC . MAC . . ARP : --arpsha . --destaddr= or -T MAC . . ff:ff:ff:ff:ff:ff ( /Broadcast) . () (multicast) . --prototype= or -y =0x0806. . --llc or -L RFC 1042 LLC/SNAP 802.2. arp-scan ARP Ethernet-II IEEE 802.2 . --vlan= or -Q 802.1Q VLAN . 0 4095 . arp-scan ARP 802.1Q . (Misc Options) --limit= or -M . arp-scan 1 . . --pcapsavefile= or -W pcap . ARP . --snap= or -n pcap (snap length) . =. . . --retry-send= or -Y =. --retry-send-interval= or -E . "u" . =. --padding= or -A (padding) . ARP . (EXIT STATUS) arp-scan 0 >0 . --limit arp-scan . (FILES) /usr/share/arp-scan/ieee-oui.txt IEEE ( OUI) . /etc/arp-scan/mac-vendor.txt MAC . (EXAMPLES) (Simple Scan) IPv4 . $ arp-scan --localnet Interface: eth0, type: EN10MB, MAC: 50:65:f3:f0:6d:7c, IPv4: 10.0.0.106 Starting arp-scan 1.9.9 with 256 hosts (https://github.com/royhills/arp-scan) 10.0.0.14 a4:1f:72:7f:25:bb Dell Inc. 10.0.0.22 10:60:4b:73:43:de Hewlett Packard 10.0.0.74 00:0c:29:90:07:e9 VMware, Inc. 10.0.0.75 00:0c:29:66:9e:c2 VMware, Inc. 10.0.0.76 00:0c:29:d0:e1:ea VMware, Inc. 10.0.0.82 9c:b6:54:bb:f3:ec Hewlett Packard 10.0.0.84 00:21:9b:fd:b9:b3 Dell Inc. 10.0.0.85 00:02:b3:eb:5a:f8 Intel Corporation 10.0.0.91 00:9c:02:a5:7b:29 Hewlett Packard 10.0.0.92 d4:ae:52:d0:07:6f Dell Inc. 10.0.0.93 d4:ae:52:d0:04:9b Dell Inc. 10.0.0.96 9c:b6:54:bb:f5:35 Hewlett Packard 10.0.0.97 00:0c:29:0e:95:20 VMware, Inc. 10.0.0.104 50:65:f3:f0:70:a4 Hewlett Packard 15 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.9.9: 256 hosts scanned in 1.532 seconds (167.10 hosts/sec). 14 responded (Output Formatting) 10.0.0.0/24 eth0. . $ arp-scan -I eth0 --rtt --format='|${ip;-15}|${mac}|${rtt;8}|' 10.0.0.0/24 Interface: eth0, type: EN10MB, MAC: 50:65:f3:f0:6d:7c, IPv4: 10.0.0.106 Starting arp-scan 1.9.9 with 256 hosts (https://github.com/royhills/arp-scan) |10.0.0.14 |a4:1f:72:7f:25:bb| 0.280| |10.0.0.22 |10:60:4b:73:43:de| 0.293| |10.0.0.74 |00:0c:29:90:07:e9| 0.380| |10.0.0.75 |00:0c:29:66:9e:c2| 0.311| |10.0.0.76 |00:0c:29:d0:e1:ea| 0.326| |10.0.0.82 |9c:b6:54:bb:f3:ec| 0.216| |10.0.0.84 |00:21:9b:fd:b9:b3| 0.244| |10.0.0.85 |00:02:b3:eb:5a:f8| 0.244| |10.0.0.91 |00:9c:02:a5:7b:29| 0.209| |10.0.0.92 |d4:ae:52:d0:07:6f| 0.289| |10.0.0.93 |d4:ae:52:d0:04:9b| 0.278| |10.0.0.96 |9c:b6:54:bb:f5:35| 0.255| |10.0.0.97 |00:0c:29:0e:95:20| 0.288| |10.0.0.104 |50:65:f3:f0:70:a4| 0.263| 14 packets received by filter, 0 packets dropped by kernel Ending arp-scan 1.9.9: 256 hosts scanned in 2.032 seconds (125.98 hosts/sec). 14 responded CSV (CSV Output) --plain . $ arp-scan -I eth0 --plain --format='${ip},${mac},"${vendor}"' 10.0.0.0/24 10.0.0.14,a4:1f:72:7f:25:bb,"Dell Inc." 10.0.0.22,10:60:4b:73:43:de,"Hewlett Packard" 10.0.0.74,00:0c:29:90:07:e9,"VMware, Inc." 10.0.0.75,00:0c:29:66:9e:c2,"VMware, Inc." 10.0.0.76,00:0c:29:d0:e1:ea,"VMware, Inc." 10.0.0.82,9c:b6:54:bb:f3:ec,"Hewlett Packard" 10.0.0.84,00:21:9b:fd:b9:b3,"Dell Inc." 10.0.0.85,00:02:b3:eb:5a:f8,"Intel Corporation" 10.0.0.91,00:9c:02:a5:7b:29,"Hewlett Packard" 10.0.0.92,d4:ae:52:d0:07:6f,"Dell Inc." 10.0.0.93,d4:ae:52:d0:04:9b,"Dell Inc." 10.0.0.96,9c:b6:54:bb:f5:35,"Hewlett Packard" 10.0.0.97,00:0c:29:0e:95:20,"VMware, Inc." 10.0.0.104,50:65:f3:f0:70:a4,"Hewlett Packard" (SEE ALSO) get-oui(1) arp-fingerprint(1) http://www.royhills.co.uk/wiki arp-scan. https://github.com/royhills/arp-scan arp- scan. January 14, 2023 ARP-SCAN(1)