MCP server for network scanning, HTTP and SSH — plus a standalone high-speed scanner. Pure Rust; the scan engine is built in and needs no zmap/masscan binaries.
Quick links: docs/README.md (full guide) · docs/TOOLS.md · docs/ARCHITECTURE.md · docs/MIGRATION.md · docs/THREAT_MODEL.md · docs/PERFORMANCE.md
cargo build --release
# MCP server (config.toml in the working directory, or set MCP_CONFIG)
target/release/mcp-netscan
# Standalone scan (needs CAP_NET_RAW; see [node] in config.toml)
sudo target/release/zscan 10.0.0.0/24 -p 22,80,443 -i eth0 \
--router-mac <gateway-mac> --adapter-ip <your-ip> --bannersEvery tool runs in-process, in pure Rust — nothing shells out to a scanner binary.
net_scan— port scanning with the built-in engine: TCP SYN/connect/ACK/FIN/ NULL/XMAS/Maimon/window, UDP (dns/mdns/snmp/ntp/ssdp/memcached), ICMP discovery, the-sOIP-protocol scan, service/version detection, and nmap-style output (normal/xml/grepable/json). Full parity notes in docs/PARITY.md.dns_query,dns_bruteforce,dns_zone_transfer,subdomain_permute— the DNS suite.redis_check,smtp_enum,ftp_probe,ssh_audit,tls_scan,ike_scan— per-service probes and audits.http_probe,web_crawl,web_tech,waf_detect,security_headers,cors_check— web reconnaissance.web_fuzz,param_discover,js_endpoints,xss_scan,sqli_scan,ssti_scan,jwt_inspect,open_redirect,cms_detect,graphql_probe— web auditing.ping_sweep,nbtscan,snmp_check,snmp_walk,packet_send— host and service discovery, plus raw packet crafting.secret_scan,cewl,hash_identify,dedup_lines,json_flatten— secrets and pipeline utilities.http_request,ssh— HTTP and SSH clients.
Each suite is configured under [tools.<suite>] with a shared limits envelope
(enabled, timeout_secs, max_output_bytes, max_concurrency,
max_targets, max_requests_per_sec). Limits only ever tighten, and the
per-credential quota chain still applies on top. See
docs/TOOLS.md for the inventory and the list of what is
deliberately out of scope.
Operators can add their own tools without touching the code:
[[tools.custom]] declares an external command with argument and value
allow-lists, and an in-process plugin implements the same ToolHandler trait —
both inherit the same quotas, timeouts and output caps.
cargo test --workspace # privileged veth/netns tests skip without root
scripts/test-all.sh # fmt + clippy + tests (+ live tests when STORE_IT=1)
scripts/lab.sh up | down # veth + netns lab for the engine integration tests