
Local Area Network discovery tool with an interactive Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way. Knock Knock.. who's there? 🚪
Local Area Network discovery tool with an interactive Terminal User Interface (TUI) written in Go. Discover, explore, and understand your LAN in an intuitive way.
Whosthere performs unprivileged, concurrent scans using mDNS and SSDP scanners. Additionally, it sweeps the local subnet by attempting TCP/UDP connections to trigger ARP resolution, then reads the ARP cache to identify devices on your Local Area Network. This technique populates the ARP cache without requiring elevated privileges. All discovered devices are enhanced with OUI lookups to display manufacturers when available.
Whosthere provides a friendly, intuitive way to answer the question every network administrator asks: "Who's there on my network?"

Via Homebrew with brew:
brew install whosthere
On NixOS with nix:
nix profile install nixpkgs#whosthere
On Arch Linux with yay:
yay -S whosthere-bin
If your package manager is not listed you can always install with Go:
go install github.com/ramonvermeulen/whosthere@latest
Or build from source:
git clone https://github.com/ramonvermeulen/whosthere.git
cd whosthere
make build
Additionally, you can download pre-built binaries from the releases page.
Run the TUI for interactive discovery:
whosthere
Run as cli to do a single scan and output results:
whosthere scan -t 5
Output results to a JSON file:
whosthere scan -t 5 --json --pretty > devices.json
Run as a daemon with HTTP API:
whosthere daemon --port=8080
Import aliases in bulk from a file, or export the current ones:
whosthere aliases import ./aliases.yaml
whosthere aliases export --stdout
Additional command line options can be found by running:
whosthere --help
| Key | Action |
|---|---|
/ | Start regex search |
k | Up |
j | Down |
g | Go to top |
G | Go to bottom |
y | Copy IP of selected device |
Y | Copy MAC of selected device |
enter | Show device details |
CTRL+t | Toggle theme selector |
CTRL+i | Toggle interface selector |
CTRL+c/q | Stop application |
ESC | Clear search / Go back |
p (details view) | Start port scan on device |
tab (modal view) | Switch button selection |
Whosthere supports multiple configuration methods with the following precedence (highest to lowest):
whosthere --help for available flags.WHOSTHERE__. See Configuration via Environment Variables.DefaultConfig() in config.go.Whosthere looks for the configuration file in the following order, using the first one found:
--config flag or WHOSTHERE_CONFIG environment variable$XDG_CONFIG_HOME/whosthere/config.yaml (if XDG_CONFIG_HOME is set)~/.config/whosthere/config.yaml (default location)Example configuration:
# Uncomment the next line to configure a specific network interface - uses OS default if not set
# network_interface: eth0
# When enabled, devices from all network interfaces are shown and persist when switching interfaces
# Note: if two interfaces share the same subnet (e.g. both use 192.168.1.x), devices may get merged
# since they are identified by IP address. Use with caution on overlapping subnets.
all_interfaces: false
# Optional IPv4 CIDR subnets to sweep. When set, the sweeper skips the auto-detected interface subnet unless it is listed here.
# target_subnets: ["10.0.0.0/24", "10.0.1.0/24"]
# WARNING: scanning subnets larger than /16 sends packets to 65535+ IPs per subnet. Enable only if you understand the traffic implications. Consider using smaller /24 subnets for targeted scanning.
# scan_large_subnets: false
# How often to run discovery scans
scan_interval: 20s
# Maximum timeout for each scan, recommended to be less than the scan interval
scan_timeout: 10s
scanners:
mdns:
enabled: true
ssdp:
enabled: true
arp:
enabled: true
sweeper:
enabled: true
interval: 5m
timeout: 20s
port_scanner:
timeout: 5s
# List of TCP ports to scan on discovered devices
tcp: [21, 22, 23, 25, 80, 110, 135, 139, 143, 389, 443, 445, 993, 995, 1433, 1521, 3306, 3389, 5432, 5900, 8080, 8443, 9000, 9090, 9200, 9300, 10000, 27017]
splash:
enabled: true
delay: 1s
theme:
# When disabled, the TUI will use the terminal it's default ANSI colors
# Also see the NO_COLOR environment variable to completely disable ANSI colors
enabled: true
# See the complete list of available themes at https://github.com/ramonvermeulen/whosthere/tree/main/internal/ui/theme/theme.go
# Set name to "custom" to use the custom colors below
# For any color that is not configured it will take the default theme value as fallback
name: default
# Disable ANSI colors completely, overrides theme.enabled
# Can also be set via NO_COLOR or WHOSTHERE__THEME__NO_COLOR environment variables
# no_color: false