Angry IP Scanner: What It Does, How to Install It and How to Use It
Angry IP Scanner is a fast, lightweight, and open-source network scanner used for IP address and port scanning. It is essential for network management, cybersecurity assessments, and identifying unauthorized devices. Compatible with Windows, macOS, and Linux, it offers customizable scanning and easy-to-export results. With both GUI and CLI support, it caters to users of all skill levels.
Quick answer: Angry IP Scanner is a free, open-source network scanner for Windows, macOS and Linux. You give it an IP range, and it pings each address and reports which hosts are alive, with optional hostname, MAC address and open-port details. Results export to CSV, TXT or XML. It is fast and simple, but it does not detect service versions or vulnerabilities like Nmap does.
Key takeaways
- Use Angry IP Scanner to answer "what is on this network?" quickly, for example to find a device's IP or spot unknown hosts.
- It checks one thing per column, called a fetcher: ping, hostname, ports, MAC and more. You choose which to enable.
- A host that blocks ping can look dead. Switch the ping method or add a port check before concluding nothing is there.
- Scan only networks you own or have written permission to test. Unauthorised scanning can break the law under India's IT Act, 2000.
What Angry IP Scanner does
Angry IP Scanner, also called ipscan, sends probes to every address in a range and shows the results in a table. It was written in Java, uses multiple threads to scan quickly, and is distributed from its official site, angryip.org. It has a graphical interface and a command-line mode.
It answers three simple questions: which addresses respond, what are they called, and which ports are open. For anything deeper, such as OS detection, service versions or scripted checks, use Nmap. See what Nmap is and how it is used.
Main features
| Feature | What it gives you |
|---|---|
| Ping scan | Shows which addresses answer, with response time |
| Hostname fetcher | Reverse DNS name where one exists |
| Port scan | Open ports from a list or range you choose |
| MAC address fetcher | Hardware address for hosts on your local subnet |
| NetBIOS and other fetchers | Windows names and extra details, depending on the version |
| Export | CSV, TXT, XML and IP-port lists |
| Plugins | Extra fetchers and exporters from the community |
The set of fetchers varies by release, so open the fetcher selector in the tool to see what your version offers.
How to install it
Download only from the official site and check the file matches the release listed there.
Windows
Download the installer, run it and follow the wizard. A portable ZIP version is also available, which you can run from a folder without installing.
macOS
Download the macOS package and drag the app into Applications. If macOS blocks it, open System Settings, then Privacy and Security, and allow it. Do this only for a download you trust.
Linux
Download the .deb (Debian, Ubuntu, Kali) or .rpm (RHEL family) package and install it with your package manager, so that dependencies are handled for you.
# Debian, Ubuntu, Kali
sudo apt install./ipscan_*_amd64.deb
# RHEL, Rocky, AlmaLinux, Fedora
sudo dnf install./ipscan-*.rpm
ipscan
Recent packages include or pull in the Java runtime they need. If yours does not, install a current JRE first. Some ping modes need elevated privileges on Linux, so if ICMP results look empty, try running with sudo in your lab.
How to run your first scan
- Find your own range first. On Linux, run
ip -4 addr. A typical home network is192.168.1.0/24. - Open Angry IP Scanner and enter the start and end IP, or choose the netmask option.
- Open Tools, then Preferences, to pick the ping method and the ports to check, for example 22, 80, 443 and 3389.
- Click Start and wait for the progress bar.
- Sort by status. Live hosts are marked, and the other columns fill in.
- Export with Scan, then Export all, to keep a record.
Reading the results
- Alive with a hostname: a managed device, probably known to you.
- Alive with no hostname: common for phones and IoT devices. Check the MAC vendor and compare against your device list.
- Open port 3389 or 22 on something unexpected: investigate. Remote access ports on unknown hosts are worth a closer look.
- Dead but you know it exists: a firewall may be dropping ping. Try a TCP or UDP method, or scan its known port.
Where it is useful
- Home or lab: find the IP of a printer, camera or Raspberry Pi.
- Network inventory: a quick list of live hosts to compare against an asset register.
- Troubleshooting: check whether a server responds after a change, or hunt for an IP conflict.
- Security checks on your own network: spot rogue devices and unexpected open ports.
Limits and cautions
- It does not identify service versions or vulnerabilities, so it is a discovery tool, not an assessment tool.
- Quick, wide scans can alert IDS tools and annoy administrators. Tell the network owner first.
- MAC addresses show only for hosts on the same Layer 2 segment.
- Scanning ranges you do not own is unauthorised. Use your own network or lab VMs.
Angry IP Scanner or Nmap?
| Angry IP Scanner | Nmap | |
|---|---|---|
| Interface | Simple graphical table | Command line, with Zenmap GUI available separately |
| Best for | Quick "who is on my network" checks | Deep discovery, service and OS detection, scripting |
| Learning curve | Minutes | Days to weeks |
| Security testing depth | Light | Extensive |
Most professionals use both: Angry IP Scanner for a quick look, Nmap when they need answers. The Nmap reference guide is the best next read.
Next steps
Once discovery feels easy, learn what to do with the results in network scanning in cybersecurity. For structured hands-on practice, see the Computer Network course.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0