Zond is a network scanner for discovery and auditing. It finds the hosts on a
network, their open ports and the services behind them, and shows the CVEs
that still apply to each service.
It is the official command-line interface to
zond-engine, a scanning
library you can build on.
Linux, macOS and Windows. Currently in beta.
zond-demo.mp4
Debian, Ubuntu, Kali: grab the .deb from the latest release.
sudo apt install ./zond_*.debFedora: grab the .rpm from the same page.
sudo dnf install ./zond-*.rpmArch Linux: from the AUR.
yay -S zondmacOS:
brew install zond-rs/tap/zondWindows: run zond-<version>-setup.exe from the release page. It needs Npcap.
Nix or NixOS: there is a package in nixpkgs.
The latest release usually lands in the unstable channel first.
nix-env -iA nixos.zondAnything else, with Rust 1.93 or newer:
cargo install zond-cliYou usually don't need sudo on Linux or macOS. The Linux packages give zond
the network access it needs, and where it can't get that access, it falls back
to ordinary connections and tells you so.
zond discover lan # which devices on my network are up?
zond scan 192.168.1.10 # open ports and what's running on them
zond scan 192.168.1.0/24 -F # quick pass over a whole subnet
zond scan 192.168.1.10 -p- -A # every port, the OS and deeper checks
zond scan lan --pipe # one line per host, for scriptsTargets can be addresses, ranges like 10.0.0.1-50, CIDR blocks, hostnames
or lan. Every command takes -h for a short summary and --help for the
full story.
Getting the most out of it without sudo
Some scan types and local discovery need raw sockets. Zond works without them, but finds less.
- Linux, installed with
cargo: grant them once withsudo setcap cap_net_raw,cap_net_admin+eip "$(command -v zond)" - macOS:
brew install --cask wireshark-chmodbpf, then log out and back in. - Windows: run zond from an Administrator terminal.
| Command | What it does |
|---|---|
discover |
Finds which hosts on a network are up. |
scan |
Finds open ports, identifies services and checks them for vulnerabilities. |
listen |
Watches a network link and records what it hears. Sends nothing. |
resume |
Continues a scan, discovery or watch that was interrupted. |
journal |
Lists the scans saved on this machine. |
read |
Prints an old scan again, or exports it to JSON, CSV, HTML or nmap XML. |
diff |
Shows what changed between two scans. |
merge |
Combines several scans into one report. |
detections |
Shows which checks a scan would run, without scanning. |
update |
Downloads the latest vulnerability data. |
completions |
Prints shell completions for bash, zsh, fish, PowerShell or elvish. |
help |
Help for any command, plus topics like targets, ports and settings. |
Zond is new, and beta testers are what make it better. If something breaks, confuses you or reports a vulnerability that isn't there, open an issue.
Found a security problem in zond itself? Please follow SECURITY.md instead of opening a public issue.
Only scan networks you own or have permission to scan.
AGPL-3.0-or-later. A commercial license is available for cases where the AGPL doesn't fit: licensing@zond.rs.
Ubuntu security data in release builds is Canonical's, under CC BY-SA 4.0 (notice).