Skip to content

Zond

Crates.io License: AGPL v3 Rust Version

Zond is a network scanner for discovery and auditing. It finds the hosts on a network, their open ports and the services behind them, and shows the CVEs that still apply to each service.
It is the official command-line interface to zond-engine, a scanning library you can build on.

Linux, macOS and Windows. Currently in beta.

zond-demo.mp4

Install

Debian, Ubuntu, Kali: grab the .deb from the latest release.

sudo apt install ./zond_*.deb

Fedora: grab the .rpm from the same page.

sudo dnf install ./zond-*.rpm

Arch Linux: from the AUR.

yay -S zond

macOS:

brew install zond-rs/tap/zond

Windows: run zond-<version>-setup.exe from the release page. It needs Npcap.

Nix or NixOS: there is a package in nixpkgs. The latest release usually lands in the unstable channel first.

nix-env -iA nixos.zond

Anything else, with Rust 1.93 or newer:

cargo install zond-cli

Quick start

You usually don't need sudo on Linux or macOS. The Linux packages give zond the network access it needs, and where it can't get that access, it falls back to ordinary connections and tells you so.

zond discover lan               # which devices on my network are up?
zond scan 192.168.1.10          # open ports and what's running on them
zond scan 192.168.1.0/24 -F     # quick pass over a whole subnet
zond scan 192.168.1.10 -p- -A   # every port, the OS and deeper checks
zond scan lan --pipe            # one line per host, for scripts

Targets can be addresses, ranges like 10.0.0.1-50, CIDR blocks, hostnames or lan. Every command takes -h for a short summary and --help for the full story.

Getting the most out of it without sudo

Some scan types and local discovery need raw sockets. Zond works without them, but finds less.

  • Linux, installed with cargo: grant them once with sudo setcap cap_net_raw,cap_net_admin+eip "$(command -v zond)"
  • macOS: brew install --cask wireshark-chmodbpf, then log out and back in.
  • Windows: run zond from an Administrator terminal.

Commands

Command What it does
discover Finds which hosts on a network are up.
scan Finds open ports, identifies services and checks them for vulnerabilities.
listen Watches a network link and records what it hears. Sends nothing.
resume Continues a scan, discovery or watch that was interrupted.
journal Lists the scans saved on this machine.
read Prints an old scan again, or exports it to JSON, CSV, HTML or nmap XML.
diff Shows what changed between two scans.
merge Combines several scans into one report.
detections Shows which checks a scan would run, without scanning.
update Downloads the latest vulnerability data.
completions Prints shell completions for bash, zsh, fish, PowerShell or elvish.
help Help for any command, plus topics like targets, ports and settings.

Feedback

Zond is new, and beta testers are what make it better. If something breaks, confuses you or reports a vulnerability that isn't there, open an issue.

Found a security problem in zond itself? Please follow SECURITY.md instead of opening a public issue.

Only scan networks you own or have permission to scan.

License

AGPL-3.0-or-later. A commercial license is available for cases where the AGPL doesn't fit: licensing@zond.rs.

Ubuntu security data in release builds is Canonical's, under CC BY-SA 4.0 (notice).

About

The official CLI for Zond Engine. Discover hosts, scan ports, fingerprint services, and see what changed since the last scan.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages