Host discovery, port scan, CVE prioritization by real-world exploitation, AI-powered recommendations and active pentesting — in a single standalone Windows APP. No cloud, all data local.
↓ 0 downloads
SHA256:
From device discovery to AI-powered remediation guidance — in a single standalone tool.
ICMP ping, TCP connect fallback for firewalled hosts, plus SSDP/mDNS for UPnP and Bonjour devices with friendly names.
Parallel TCP connect scan with banner grabbing and service/version detection — pure Python, no nmap or drivers required.
CISA KEV flags actively exploited flaws, EPSS estimates exploitation likelihood — going beyond plain CVSS scores.
Sends scan summary to Anthropic, OpenAI, OpenRouter or local Ollama — returns executive summary and remediation plan.
Every scan saved. Compare two runs: risk delta, new/removed hosts, changed service versions, new CVEs.
nmap NSE vuln scripts and 5,000+ nuclei templates: SSL/TLS, SMB, default credentials, HTTP headers and more.
Detects your public IP with geo, ISP and ASN info and checks open external ports and CVEs from the outside.
7-day free trial, then Polar.sh license. All data stays local during trial — no registration, no email required.
NVD API key, AI provider config (Anthropic / OpenAI / OpenRouter / Ollama) — stored locally and encrypted at rest via Windows DPAPI.
Auto, force nmap or pure native — your choice per scan. nmap unlocks OS detection and deeper fingerprints.
HTML, Excel, JSON, CSV and PDF — all locally generated. CSV in UTF-8 BOM for Excel, PDF as a formatted A4 report with severity-coloured host details and full CVE breakdown.
Visual map of all discovered hosts with severity coloring, zoom and pan — export as PNG or SVG for reports and documentation.
Full English and German interface — switch anytime in Settings (takes effect after restart).
Classifies every host into a device type — router, server, NAS, printer, IP camera, smart speaker, smart home and more — from vendor, ports and banners.
Right-click any host to send a Wake-on-LAN magic packet. Assign persistent custom labels and group tags per MAC address — survive reboots and IP changes.
Dashboard tab shows host-count trends and CVE/critical bars over time. DHCP/ARP lease overview and per-host firewall detection (stealth vs. open) via right-click.
After a scan, send your results to your preferred AI provider — Anthropic Claude, OpenAI GPT-4o, OpenRouter, or a fully local Ollama instance. LANsentry builds a structured prompt from your findings and returns a clear executive summary, prioritized risk list and actionable remediation steps.
Not every high-CVSS CVE is dangerous — and some low-scored ones are actively exploited in the wild. LANsentry enriches every finding with CISA KEV and EPSS data and surfaces the most critical issues first, so you know exactly where to act.
Compare any scan with a previous run and instantly see what changed — new devices joined the network, new open ports appeared, service versions updated, and new CVEs discovered. A clear risk delta shows whether your security posture improved or worsened.
LANsentry doesn't just list open ports — it classifies every host into a device type, combining MAC vendor OUI lookups, open ports, service banners and HTTP/SNMP fingerprints. Routers, NAS boxes, printers, IP cameras, smart speakers and smart-home gadgets are labeled automatically, so you immediately know what you're looking at.
LANsentry is designed from the ground up to be a local-first tool. Here is exactly what leaves your machine and what does not.
All scan results are stored in a local SQLite database — never uploaded to any server.
The only outbound connections: CVE lookups to NVD/CIRCL (standard security DB queries) and Polar.sh license validation — only when you enter a license key.
AI analysis is strictly opt-in: it sends a structured text summary (no raw packet data) to your chosen AI provider — only when you explicitly click "Analyze". Using Ollama means zero external connections.
No telemetry, no analytics, no crash reporting to external servers. What happens on your network stays on your network.
API keys are encrypted at rest using Windows DPAPI, tied to your Windows user account — not stored as plain text on disk.
A full-featured trial, no strings attached.
Use this tool only on networks for which you have explicit written permission. Unauthorized scanning is a criminal offense (e.g. § 202c StGB in Germany). nmap/Npcap are not bundled for licensing reasons; nuclei (MIT) may be bundled.
Download the Windows app and start your 7-day free trial.
↓ 0 downloads