Skip to content

Masscan

Asynchronous Internet-scale port scanner

CommunityNetworking· Discovery & ReconAdvancedOpen sourceEntry revised 6 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Arch
  • Source

Community. Contributor-submitted. Not every claim has been re-checked. Cross-check against the upstream documentation before relying on a command.

This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Masscan is built for rate, not subtlety: it sends SYN probes from its own stack at tens of thousands of packets per second to find which addresses answer on a port.

It is the tool for scanning a range you are responsible for — an owned /16, a hosting subnet — to learn what is exposed. Because it does not complete handshakes by default, its results need confirmation with a connect scan before anything goes in a report.

Supported platforms

6

Documented install or usage guidance

Learning curve

advanced

Difficulty of becoming productive, not of the underlying theory

Tags

scanning, range, syn, rate

Dataset entry

masscan.ts

Reviewed 2026-01-06

Installation

Grouped by platform. Elevation requirements are marked per method.

Homebrew

AlternativeHomebrew
brew install masscan

Package availability follows your distribution and enabled repositories. Entry revised 6 Jan 2026 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Scan a subnet at a fixed rate

bash

Probes one port across an address range with an explicit packet-per-second ceiling.

sudo masscan 192.0.2.0/24 -p80 --rate 500
  • Rate is a blast-radius control. Scan only ranges you own or are authorized to test, and coordinate with the network team.

Notes

  • Confirm each hit with `nmap -sV -p 80 <ip>`; Masscan reports what answered a SYN, not what the service is.

02Protect infrastructure with an exclude file

bash

Reads addresses to skip — printers, SCADA hosts, management interfaces.

sudo masscan 192.0.2.0/24 -p1-1024 --excludefile exclude.txt -oJ out.json

Notes

  • One line per address or CIDR. Make the exclude list part of the engagement record so both runs are comparable.

03Grab banners with the same command

bash

Completes just enough of a connection to record a service banner.

sudo masscan 192.0.2.10-192.0.2.40 -p22,80,443 --banners -oL banners.txt

04Configure source address for routed scans

bash

On Windows, or when scanning off-subnet, Masscan needs to be told the gateway and its own address.

sudo masscan 203.0.113.0/24 -p443 --adapter-ip 198.51.100.7 --adapter-gateway 198.51.100.1 --router-ip 198.51.100.1
  • Off-subnet SYN scanning depends on return-path routing. Verify the network allows it before assuming zero results means closed.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

FATAL: failed to detect any interfaces / 'couldn't open adapter'Cause 1/2

Possible causes

  • No capture library (Npcap/libpcap), or the interface name differs from what the tool expects.

Usual fix

Install Npcap on Windows with raw-socket support, or list devices with `masscan --adapter` and pass `--adapter-name`.

Scan finishes with no open ports although nmap finds someCause 2/2

Possible causes

  • Rate too high for the path (responses dropped), or return traffic goes to a different address.

Usual fix

Lower `--rate`, add `--wait 5`, and re-check a single host to separate scanner configuration from network reality.

Alternatives & comparisons

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking