The Best Network Surveillance Tool
NetFind v9.9.1 — Complete Command Reference & Operational Guide
This guide breaks down every module command in NetFind v9.9.1, detailing how to execute it, what it does, and the underlying network mechanics behind how it works. (Note most commands that use ports reuire thatbthe port you input is open use nmap to check this)
Core Network Discovery & Reconnaissance
help
How to use it: help
What it does: Displays the interactive table of all available commands and their definitions directly in the console.
How and why it works: NetFind queries its internal command dictionary and renders an formatted Rich table, giving you an immediate visual reference of all supported syntax without stopping your session.
net.show
How to use it: net.show
What it does: Scans the active LAN and displays a formatted table of all discovered hosts with their IP address, MAC address, hardware vendor, and hostname.
How and why it works: NetFind broadcasts Layer 2 ARP (Address Resolution Protocol) request packets (ff:ff:ff:ff:ff:ff) across the local subnet. Because ARP operates below the firewall layer, active devices respond with their MAC address. NetFind maps those MAC prefixes (OUIs) against its local hardware vendor database while simultaneously running reverse DNS checks to resolve local hostnames.
net.find <IP>
How to use it: net.find 127.0.0.1
What it does: Monitors network traffic dedicated to a specific target IP to identify requested web domains in real time.
How and why it works: NetFind sets up a targeted packet capture filter on raw socket interfaces. It listens specifically for unencrypted DNS queries (Port 53) and HTTP host headers originating from the target IP, printing human-readable domain names as the user navigates the web.
net.find/all <IP>
How to use it: net.find/all 127.0.0.1
What it does: Performs a deep passive target scan to automatically extract the device owner's name, operating system type, active applications, TLS SNI endpoints, and mDNS broadcasts.
How and why it works: Combines DNS monitoring with TLS Server Name Indication (SNI) parsing on port 443. By reading the unencrypted Client Hello packet during HTTPS handshakes, it extracts encrypted domain endpoints. It also reads mDNS/Bonjour network broadcasts and HTTP User-Agent strings, parsing names to infer the device owner and classify the OS via IP TTL (Time To Live) signatures.
net.find/data <IP>
How to use it: net.find/data 127.0.0.1
What it does: Executes Advanced Data Stream Recon on a single IP, capturing deep SNI endpoints, full HTTP request paths, and real-time app telemetry.
How and why it works: Upgrades standard sniffing by hooking into Scapy’s TCP session reassembly layers. It parses HTTP request headers down to explicit URL paths (/api/v1/stream) and matches destination hostnames against a signature database of popular mobile apps and web platforms.
Omni-Target Surveillance
net.listen/all
How to use it: net.listen/all
What it does: Runs an omni-target passive scan across the entire local network, automatically identifying application activity, owner names, and secure web traffic for all connected devices simultaneously.
How and why it works: It puts the network interface into a global capture state, indexing every IP address on the LAN into an active memory map. As packets fly across the switch or Wi-Fi interface, NetFind continuously attributes background DNS, mDNS, and TLS SNI streams to their respective device owners in real time.
net.listen/data
How to use it: net.listen/data
What it does: Launches the Omni-Target Advanced Data Stream engine, pulling deep HTTP request paths, TLS endpoints, and real-time app payloads across every host on the network.
How and why it works: Processes packet payloads globally using session-aware reassembly algorithms. It continuously parses multi-packet HTTP flows and HTTPS TLS Client Hellos, giving you a top-level telemetry feed of all web and application traffic across the entire subnet.
net.listen
How to use it: net.listen
What it does: Passively sniffs local network ARP traffic to catch active hosts as they communicate or join the network.
How and why it works: Instead of sending out active probes, net.listen operates completely silently. It listens for background ARP requests and announcements (who-has / is-at), logging new devices the second their hardware interface speaks on the network.
Infrastructure & Service Auditing
net.gateway
How to use it: net.gateway
What it does: Inspects the default network gateway, displaying its IP address, MAC address, router vendor, and common administrative open ports.
How and why it works: NetFind queries the operating system route table to identify the default gateway IP, sends a direct Layer 2 ARP query to resolve its MAC address and vendor, and executes a multi-threaded socket probe against primary administrative management ports (like 80, 443, 22, 8080).
net.lookup <IP>
How to use it: net.lookup 127.0.0.1
What it does: Scans common administrative and service ports on a target IP to identify active network services.
How and why it works: Uses a high-speed ThreadPoolExecutor to perform TCP connect checks across a targeted database of ports (SSH, FTP, Web, RDP, SMB, etc.). Open ports are matched against service definitions to tell you exactly what daemons are running.
net.banner <IP> <port>
How to use it: net.banner 127.0.0.1 21 or net.banner 127.0.0.1 80
What it does: Opens a raw TCP connection to a specific port and captures its raw greeting banner or service response.
How and why it works: Connects directly via raw TCP sockets and sends standard service greeting triggers (or an HTTP HEAD request for web servers). It reads the raw byte response to reveal software versions, server types, and operating system banners.
net.cert <IP> [port]
How to use it: net.cert 127.0.0.1 or net.cert 127.0.0.1 8443
What it does: Extracts and parses SSL/TLS certificate details from HTTPS or encrypted endpoints.
How and why it works: Initiates a TLS handshake using Python’s ssl module without requiring certificate validation. It extracts the X.509 certificate payload to display the Common Name (CN), Issuer, Organization, Expiration date, and Subject Alternative Names (SANs).
net.dhcp
How to use it: net.dhcp
What it does: Listens for active DHCP traffic to detect routers, network gateways, and newly requesting clients.
How and why it works: Sets up a socket sniffer on UDP ports 67 and 68. It captures DHCPDISCOVER, OFFER, REQUEST, and ACK broadcast packets, parsing DHCP options to reveal assigned gateway IPs, DNS server configurations, and device hostname hints.
net.upnp
How to use it: net.upnp
What it does: Broadcasts SSDP queries to discover smart devices, routers, media servers, and IoT equipment advertising UPnP services.
How and why it works: Sends an HTTP M-SEARCH packet over UDP multicast to 239.255.255.250:1900. NetFind listens for unicast HTTP responses from local devices, parsing the LOCATION XML URL and server headers to expose smart TVs, routers, and IoT hardware.
Lookup Utilities & Environment Control
net.mac <MAC>
How to use it: net.mac DC:A6:32:11:22:33
What it does: Resolves a MAC address or OUI prefix to identify the hardware manufacturer.
How and why it works: Sanitizes the input string and queries NetFind’s embedded IEEE Organizationally Unique Identifier (OUI) database to match the first 3 bytes against registered hardware vendors (e.g., Apple, Raspberry Pi, VMware).
net.range
How to use it: net.range
What it does: Displays your local host IP, the current target subnet range, and OS-specific terminal guide commands.
How and why it works: Reads your active network adapter settings, calculates the netmask boundaries, and displays helper commands (ipconfig, ip route, netstat) so you can verify network routes manually on any OS.
dns.listen
How to use it: dns.listen
What it does: Passively captures all UDP Port 53 DNS queries passing through the network interface to show requested domains.
How and why it works: Filters traffic specifically for UDP port 53. It extracts DNSQR (DNS Question Records) from captured packets, giving a real-time stream of domain lookups from every host on the network.
dns.reverse <IP>
How to use it: dns.reverse 127.0.0.1
What it does: Performs a reverse DNS (PTR record) lookup to resolve an IP address into a human-readable hostname.
How and why it works: Queries the local or upstream DNS server for the PTR record corresponding to the inverted IP address structure (.in-addr.arpa), exposing registered domain hostnames.
dns.mdns
How to use it: dns.mdns
What it does: Listens for mDNS (Multicast DNS) / Bonjour service broadcasts to find local hostnames, printers, and smart home services.
How and why it works: Leverages the zeroconf engine to browse common local service types (_http._tcp, _airplay._tcp, etc.) on UDP port 5353, resolving internal .local domain names without needing a centralized DNS server.
sys.interfaces
How to use it: sys.interfaces
What it does: Lists all physical and virtual network adapters installed on your machine alongside their assigned IP addresses, netmasks, and MAC addresses.
How and why it works: Calls system kernel APIs via psutil.net_if_addrs(), mapping socket families across Windows, macOS, or Linux to give you a clear breakdown of available capture interfaces.
blue.show
How to use it: blue.show
What it does: Scans the surrounding radio spectrum for visible Bluetooth Low Energy (BLE) devices.
How and why it works: Utilizes the asynchronous bleak library to interface directly with your host machine’s Bluetooth controller, sniffing BLE advertising packets to log nearby device names, MAC addresses, and RSSI signal strengths.
set.subnet <base>
How to use it: set.subnet 10.0.0
What it does: Manually overrides the active target subnet range used for scans and monitoring.
How and why it works: Updates NetFind's internal global variable (subnet_base), immediately redirecting all ARP scans, gateway lookups, and discovery modules to target a different network segment without needing to restart the tool.
exit
How to use it: exit
What it does: Safely closes the NetFind framework console and terminates all active packet sniffers.
How and why it works: Cleans up active background threads, closes raw socket listeners, shuts down Zeroconf browsers, and restores your terminal state cleanly.