Best apps for finding unknown devices on your home network

Open the DHCP client list on a five-year-old router and the count is often ridiculous. Ours sat at 47 entries, and we could only put a name to about 12 of them. Some were obvious in retrospect: the smart TV that pings Netflix on a schedule, a Chromecast that never sleeps, an Ecobee thermostat that changed its hostname after a firmware update. Others were less obvious, like a phone marked android-xxxx that turned out to be a friend’s Pixel still remembered from a party in April. This is the case for the best apps for detecting unknown network devices: a proper desktop scanner turns a wall of MAC addresses into a labelled inventory, then tells us the moment something new joins.

We ran seven scanners on Windows 11, macOS Sonoma, and Fedora 40 against the same 47-device home LAN over ten days. The picks below cover free one-shot scans, ongoing monitors, packet-level rogue hunting, and a self-hosted option for anyone who runs a homelab.

What to look for in a network scanner

The router UI is a fine starting point. It knows every device that asked for a DHCP lease, and most modern firmware shows the MAC address and last-seen time. That is where the scanners take over. The ones worth installing add:

Quick comparison

App Best for Platforms Free tier Monitoring
Fing Desktop Ongoing inventory with new-device alerts Windows, macOS Yes Continuous, alerts on new arrivals
Angry IP Scanner A fast one-off audit Windows, macOS, Linux Yes (open-source) On-demand only
Advanced IP Scanner Windows LAN sweep with shared folders Windows Yes (free) On-demand only
Nmap (Zenmap) Deep port and service fingerprinting Windows, macOS, Linux Yes (open-source) On-demand, scriptable
Wireshark Catching a rogue device by its traffic Windows, macOS, Linux Yes (open-source) Live capture
Netdisco Self-hosted inventory that talks to switches Linux, Docker Yes (open-source) Continuous, SNMP polling
SoftPerfect Network Scanner Rich results tables with WMI and SSH probes Windows, macOS Free tier, paid unlocks On-demand
arp-scan The lightweight CLI for a scripted sweep Linux, macOS Yes (open-source) On-demand, cron-friendly

The apps

1. Fing Desktop, best for ongoing inventory with new-device alerts

Fing Desktop is the app we install first on any Windows or macOS machine that will stay on the LAN. It scans on a schedule, remembers every device it has seen, and pushes a desktop notification the moment a new MAC joins. The device cards mix OUI vendor, mDNS name, open ports, and (for anything Fing has seen before across its user base) a specific model guess like “Amazon Echo Dot (3rd Gen)”.

The free tier covers the inventory and the arrival alerts, which is exactly the part most people need. Premium adds internet outage tracking, port change alerts, and a longer scan history.

Where it falls short: no Linux client, and the model guesses lean on Fing’s cloud database, so the accuracy depends on someone else having identified that device already.

Pricing:

Platforms: Windows, macOS.

Download: fing.com/products/fing-desktop

Bottom line: the pick when the goal is a running inventory that pings us the second an unknown device shows up.

2. Angry IP Scanner, best for a fast one-off audit

Angry IP Scanner is the tool we reach for when someone hands us a router and asks “what is on this LAN right now”. A single run against 192.168.1.0/24 returns every live host with hostname, MAC vendor, ping time, and a configurable list of open ports in under a minute on a home network. It is a 12 MB Java download, open-source under GPLv2, and identical on Windows, macOS, and Linux.

The plugin system adds NetBIOS names, web server titles, and a MAC vendor lookup that reads the current OUI file from IEEE.

Where it falls short: it does not track history, so it cannot tell us what is new since yesterday. Angry IP is a scan-and-forget tool.

Pricing:

Platforms: Windows, macOS, Linux.

Download: angryip.org

Bottom line: the pick when we need a snapshot of the LAN in one minute and do not care about long-term tracking.

3. Advanced IP Scanner, best for a Windows LAN sweep with shared folders

Advanced IP Scanner is a Famatech product that has been the go-to Windows LAN tool for a long stretch. It scans a subnet, resolves NetBIOS names, lists shared folders, and offers one-click remote actions (Radmin remote control, RDP, shutdown) for any host that accepts them. For a small office LAN it is often faster to find “which machine has the shared drive we lost track of” than to open File Explorer.

The installer is a single MSI and the whole tool sits at about 20 MB.

Where it falls short: Windows only. It is closed-source freeware from a Russian company, which is worth knowing before deploying it on sensitive networks.

Pricing:

Platforms: Windows.

Download: advanced-ip-scanner.com

Bottom line: the pick on a Windows-only LAN when the audit doubles as a hunt for lost shares and printers.

4. Nmap with Zenmap, best for deep port and service fingerprinting

Nmap is the reference network scanner and the tool the other seven either wrap or borrow from. Point it at 192.168.1.0/24 with nmap -sS -sV -O and it returns every host, every open port, the exact service and version banner, and a best guess at the operating system. Zenmap is the cross-platform GUI that turns the same command line into clickable topology maps and saved profiles.

For the unknown-device hunt, nmap -A --script=broadcast is the killer combination: it fingerprints the target and runs discovery scripts that surface HomeKit accessories, DLNA renderers, Chromecast devices, and mDNS services the router UI never mentions.

Where it falls short: a full -A scan is aggressive and slow. On a busy network it can take 15 minutes, and some smart-home devices reboot under a heavy scan.

Pricing:

Platforms: Windows, macOS, Linux.

Download: nmap.org/download.html

Bottom line: the pick when a MAC address is not enough and we need to know exactly what version of what service is listening on port 8080.

5. Wireshark, best for catching a rogue device by its traffic

Wireshark is the tool for the case where a device is on the LAN, we know the MAC, and we still cannot figure out what it is. Set a capture filter for the suspect MAC, leave it running for an hour, and the traffic tells the story: a DHCP request with a specific Vendor class string, an mDNS advertisement for _googlecast._tcp, a call out to logs.tuya.com, or a TLS handshake to an S3 bucket in a specific AWS region. Any of those turns a nameless entry into a labelled one.

Getting Wireshark to see the traffic from other devices needs a port mirror on the switch or a Wi-Fi adapter in monitor mode. On a flat home network with an unmanaged switch, ARP spoofing tools like Ettercap can force traffic through the capture host, but that is a bigger commitment.

Where it falls short: the learning curve is real, and a switched network hides most traffic from a passive listener by default.

Pricing:

Platforms: Windows, macOS, Linux.

Download: wireshark.org

Bottom line: the pick when the MAC is not enough and the only way forward is to read the packets the device actually sends.

6. Netdisco, best for a self-hosted inventory that talks to switches

Netdisco is the option for anyone who runs a homelab or a small office with managed switches. It runs as a Docker container (or a Perl install on a Linux VM), polls the switches and routers over SNMP, and builds a database of every MAC address it has ever seen, which port it was on, and what its neighbour was on the other side. The web UI lets us search a MAC, see every switch port it has ever plugged into, and jump to the historical inventory.

For a wired network with even a couple of PoE switches, Netdisco answers questions the DHCP list cannot: which port is the mystery device on, and what did it look like the last five times we saw it.

Where it falls short: it needs managed switches with SNMP enabled. On a home network with a single unmanaged switch, Netdisco cannot do its main trick.

Pricing:

Platforms: Linux, Docker.

Download: netdisco.org

Bottom line: the pick when the LAN has managed switches and the inventory question is “which port is this thing on”.

7. SoftPerfect Network Scanner, best for rich result tables with WMI and SSH probes

SoftPerfect Network Scanner is the paid alternative to Advanced IP Scanner and a step up on results depth. It scans a subnet, resolves hostnames, and then reaches into each host over WMI (Windows), SNMP, or SSH to pull the current user, uptime, installed patches, and running services. The result is a spreadsheet-style table that answers most audit questions without a second tool.

The free tier is limited to 10 devices, which is enough to try the interface but not enough for the average home LAN. The one-time paid license unlocks the full scan.

Where it falls short: the 10-device free cap makes it a paid tool in practice for any real network. On Linux the tool runs under Wine rather than natively.

Pricing:

Platforms: Windows, macOS.

Download: softperfect.com/products/networkscanner

Bottom line: the pick when the audit needs to pull real host details, not just presence and open ports.

8. arp-scan, best for the lightweight CLI on Linux and macOS

arp-scan is the two-line answer to “what is on this LAN”. A single sudo arp-scan --localnet sends an ARP request to every address on the interface’s subnet and prints every reply with the MAC, IP, and vendor name from the IEEE OUI file. It runs in seconds, it does not care what firewall is in front of the hosts (ARP works at layer 2), and it fits into a shell script or a cron job trivially.

For a headless Linux box or a Raspberry Pi that sits on the LAN, arp-scan on a five-minute cron with a diff against yesterday’s output is a homemade alert-on-new-device system that costs zero dollars.

Where it falls short: ARP only works on the local subnet, so it cannot see across a router. There is no GUI and no history without extra scripting.

Pricing:

Platforms: Linux, macOS (via Homebrew).

Download: github.com/royhills/arp-scan

Bottom line: the pick for anyone comfortable in a terminal who wants a scriptable device-diff without installing a full application.

How to pick the right one

Match the tool to the job, not the other way around.

FAQ

How do I find every device on my home network?

Open the router admin page and look for a “DHCP clients” or “Attached devices” list first. That covers the devices currently holding a lease. To catch devices that use static IPs or hopped off recently, run a scanner from a machine on the same LAN. Angry IP Scanner or Fing Desktop is enough for most homes; arp-scan does the same job from a Linux terminal in one command.

How do I identify an unknown device on my router?

Start with the MAC address. The first three bytes (the OUI) point to a manufacturer, and every scanner listed above looks that up automatically. Combine the vendor with the hostname the device advertises over mDNS or NetBIOS, then check its open ports. A device from Espressif with mDNS name smart-plug-xxxx and no open ports is a Wi-Fi smart plug. If that is still not enough, run Nmap with -A against its IP, or capture ten minutes of its traffic in Wireshark to see who it is calling.

What is the difference between Fing and Nmap?

Fing is a polished inventory tool that runs on a schedule, remembers what it has seen, and alerts on new arrivals. Nmap is a low-level scanner that answers precise questions about a specific host: what ports are open, what services are behind them, and what the operating system probably is. Fing tells us that a new device joined; Nmap tells us exactly what it is running. Most serious network work uses both.

Can someone else be using my Wi-Fi without me knowing?

Yes, and it happens more than most people think. Weak or shared Wi-Fi passwords, guest networks that were never turned off, and old WPS pins are the common paths in. A scanner run against the LAN shows every current device, and comparing that list against known household devices is the fastest way to spot a freeloader. Change the Wi-Fi password and enable WPA3 if the router supports it; that logs everyone off, and the reconnects tell us which devices we actually own.

Is Nmap legal to use on my home network?

Yes. Scanning a network we own is legal in every jurisdiction we know of. The legal grey area is scanning a network we do not own without permission. On a home LAN, on the office network at work with IT’s sign-off, or against a machine we control on the internet, Nmap is fine. Aggressive scans against a random third-party network are not.

Which scanner do I install first?

Fing Desktop if we plan to leave a machine on and want alerts. Angry IP Scanner if we just want to answer one question about the LAN today and move on. Both are free, and installing them both takes about five minutes.