Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!
L0p4Map — Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites. | Kitploit
Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time interactive network topology engine. Works on both local networks and custom IPs/websites.
L0p4Map is a professional grade network monitoring tool that combines the power of nmap with a clean, modern dark UI. Designed for security researchers and network administrators who need fast, detailed visibility into their infrastructure.
No bloat. No BS. Just raw network intelligence.
Now available on Linux, Windows and macOS.
Features
Multi-Platform Support: works on Linux (Debian/Arch), Windows and macOS with the same interface and the same feature set
Continuous Monitoring: lightweight daemon/agent that passively watches ARP and mDNS traffic without needing to rescan the whole network
Alerting: real time notification when a new, unauthorized device appears on the network
Continuous SNMP Polling: periodic SNMP queries to keep device status updated in real time, without waiting for the next scan cycle
ARP Network Scan: fast host discovery with local IEEE OUI database lookup
Range Cartography: scan any IP / CIDR / range. Routed ranges are mapped via traceroute (hosts grouped under their last hop router)
Hostname Resolution: multi method detection via reverse DNS, NetBIOS (Windows) and mDNS/Avahi (Linux, Mac, IoT)
Device Fingerprinting: TTL based OS hint (Linux/macOS, Windows, network device), TCP port probing on topology relevant ports, raw SNMP sysDescr query (no external libs)
Embedded Service Fingerprinting: passively detects iLO / InfoPrint / XPort / SATO / Zebra via banner grabbing and flags them on the graph as devices known to ship with default credentials, for manual verification
Role Detection: automatic classification of each host: gateway, router, access point, switch, PC, Apple, mobile, Raspberry Pi, virtual machine, unknown, combining vendor, hostname, TTL, open ports and SNMP response
Real Network Topology Graph: hierarchical vis.js graph that reflects the actual network structure: gateway at the top, intermediate devices (routers/APs/switches) on a second tier, clients grouped below their parent. Toggleable between Hierarchical and Force Atlas layouts
Subnet Bounding Boxes: each detected subnet is drawn as a dashed overlay directly on the graph canvas, labeled with its CIDR
Typed Edges: three visually distinct link types: uplink (gateway to internet), backbone (intermediate device to gateway), client link (device to parent)
Topology Panel: live overlay showing subnet, gateway IP, total devices and intermediate device count
Full nmap Integration: SYN scan, UDP, OS detection, service version, NSE scripts
Make sure nmap and Npcap are installed and available in the system PATH before launching the tool.
Usage
Linux and macOS
Launch the tool with root privileges:
root@kitploit:~
sudo ./L0p4Map.sh
Windows
Open a terminal (PowerShell or CMD) as Administrator, then:
root@kitploit:~
venv\Scripts\activate
python L0p4Map.py
Workflow
Select the network interface from the toolbar dropdown
Press [ SCAN ] to discover all devices: each host is fingerprinted via TTL, port probing and SNMP
Click a device to see details and run quick actions (ping, traceroute, port scan)
Switch to Graph to explore the real network topology: hover nodes for full device info, double click to assign a custom label
Toggle between [ HIERARCHICAL ] and [ FORCE ATLAS ] layout from the graph view
Use Attack Surface to run a deep nmap + vulners scan on any host and review CVEs
Use Traffic Analyzer to capture live packets, filter by device or protocol, and export to CSV
Enable [ LIVE ] in the graph view to keep the topology updated automatically
Enable Continuous Monitoring to keep the agent passively listening on ARP/mDNS and receive alerts on new devices, without having to restart a full scan
Legal Disclaimer
This tool is designed for authorized network auditing only. Only use L0p4Map on networks you own or have explicit permission to test. Unauthorized scanning is illegal.