
whosthere v0.8.3
用Go编写的局域网发现工具,具有交互式终端用户界面(TUI)。以直观的方式发现、探索和理解你的局域网。咚咚咚.. 谁在那儿?🚪
Whosthere
使用 Go 编写的局域网发现工具,带有交互式终端用户界面(TUI)。 以直观的方式发现、探索和理解你的局域网。
Whosthere 使用 mDNS 和 SSDP 扫描器执行非特权、并发扫描。此外,它通过尝试 TCP/UDP 连接来触发 ARP 解析,从而扫描本地子网,然后读取 ARP 缓存 以识别局域网中的设备。此技术无需提升权限即可填充 ARP 缓存。所有发现的设备都会通过 OUI 查询进行增强,以在可用时显示制造商信息。
Whosthere 提供了一种友好、直观的方式来回答每位网络管理员都会问的问题:“我的网络上有谁?”

功能特性
- 交互式 TUI: 直观地导航和探索发现的设备。
- 快速且并发: 同时利用多种发现方法。
- 无需提升权限: 完全在用户空间运行。
- 设备信息增强: 使用 OUI 查询显示设备制造商。
- 集成端口扫描器: 对发现的主机进行可选的服务发现(仅在有权限的情况下扫描设备!)。
- 带 HTTP API 的守护进程模式: 在后台运行并与其他工具集成。
- 主题与配置: 通过 YAML 配置个性化外观和行为。
安装
通过 Homebrew 使用 brew:
brew install whosthere
在 NixOS 上使用 nix:
nix profile install nixpkgs#whosthere
在 Arch Linux 上使用 yay:
yay -S whosthere-bin
如果你的包管理器未列出,你始终可以使用 Go 安装:
go install github.com/ramonvermeulen/whosthere@latest
或者从源码构建:
git clone https://github.com/ramonvermeulen/whosthere.git
cd whosthere
make build
此外,你可以从 releases 页面 下载预构建的二进制文件。
使用方法
运行 TUI 进行交互式发现:
whosthere
以 CLI 模式运行以执行单次扫描并输出结果:
whosthere scan -t 5
将结果输出到 JSON 文件:
whosthere scan -t 5 --json --pretty > devices.json
以守护进程模式运行并启用 HTTP API:
whosthere daemon --port=8080
可以通过运行以下命令查看其他命令行选项:
whosthere --help
按键绑定(TUI)
| 按键 | 操作 |
|---|---|
/ | 开始正则搜索 |
k | 向上 |
j | 向下 |
g | 跳到顶部 |
G | 跳到底部 |
y | 复制所选设备的 IP |
Y | 复制所选设备的 MAC |
enter | 显示设备详情 |
CTRL+t | 切换主题选择器 |
CTRL+i | 切换接口选择器 |
CTRL+c/q | 停止应用程序 |
ESC | 清除搜索 / 返回 |
p(详情视图) | 对设备启动端口扫描 |
tab(模态视图) | 切换按钮选择 |
配置
Whosthere 支持多种配置方法,优先级如下(从高到低):
- 命令行标志 - 最高优先级。查看
whosthere --help了解可用标志。 - 环境变量 - 以
WHOSTHERE__为前缀。参见 通过环境变量配置。 - 配置文件 - YAML 配置文件。参见 配置文件。
- 默认值 - 回退默认值。参见 config.go 中的
DefaultConfig()。
配置文件
Whosthere 按以下顺序查找配置文件,使用找到的第一个:
- 通过
--config标志或WHOSTHERE_CONFIG环境变量指定的路径 $XDG_CONFIG_HOME/whosthere/config.yaml(如果设置了XDG_CONFIG_HOME)~/.config/whosthere/config.yaml(默认位置)
示例配置:
# Uncomment the next line to configure a specific network interface - uses OS default if not set
# network_interface: eth0
# When enabled, devices from all network interfaces are shown and persist when switching interfaces
# Note: if two interfaces share the same subnet (e.g. both use 192.168.1.x), devices may get merged
# since they are identified by IP address. Use with caution on overlapping subnets.
all_interfaces: false
# Optional IPv4 CIDR subnets to sweep. When set, the sweeper skips the auto-detected interface subnet unless it is listed here.
# target_subnets: ["10.0.0.0/24", "10.0.1.0/24"]
# WARNING: scanning subnets larger than /16 sends packets to 65535+ IPs per subnet. Enable only if you understand the traffic implications. Consider using smaller /24 subnets for targeted scanning.
# scan_large_subnets: false
# How often to run discovery scans
scan_interval: 20s
# Maximum timeout for each scan, recommended to be less than the scan interval
scan_timeout: 10s
scanners:
mdns:
enabled: true
ssdp:
enabled: true
arp:
enabled: true
sweeper:
enabled: true
interval: 5m
timeout: 20s
port_scanner:
timeout: 5s
# List of TCP ports to scan on discovered devices
tcp: [21, 22, 23, 25, 80, 110, 135, 139, 143, 389, 443, 445, 993, 995, 1433, 1521, 3306, 3389, 5432, 5900, 8080, 8443, 9000, 9090, 9200, 9300, 10000, 27017]
splash:
enabled: true
delay: 1s
theme:
# When disabled, the TUI will use the terminal it's default ANSI colors
# Also see the NO_COLOR environment variable to completely disable ANSI colors
enabled: true
# See the complete list of available themes at https://github.com/ramonvermeulen/whosthere/tree/main/internal/ui/theme/theme.go
# Set name to "custom" to use the custom colors below
# For any color that is not configured it will take the default theme value as fallback
name: default
# Disable ANSI colors completely, overrides theme.enabled
# Can also be set via NO_COLOR or WHOSTHERE__THEME__NO_COLOR environment variables
# no_color: false
# Custom theme colors (uncomment and set name: custom to use)
# primitive_background_color: "#000a1a"
# contrast_background_color: "#001a33"
# more_contrast_background_color: "#003366"
# border_color: "#0088ff"
# title_color: "#00ffff"
# graphics_color: "#00ffaa"
# primary_text_color: "#cceeff"
# secondary_text_color: "#6699ff"
# tertiary_text_color: "#ffaa00"
# inverse_text_color: "#000a1a"
# contrast_secondary_text_color: "#88ddff"
环境变量
通用环境变量
| 变量 | 描述 |
|---|---|
WHOSTHERE_CONFIG | 配置文件的路径,用于覆盖默认位置。 |
WHOSTHERE_LOG | 设置日志级别(例如 debug、info、warn、error)。默认为 info。 |
NO_COLOR | 在 TUI 中禁用 ANSI 颜色。 |
通过环境变量配置
YAML 配置中可用的任何配置选项,都可以通过使用 WHOSTHERE__ 前缀(注意是双下划线)的环境变量进行设置。嵌套配置键由双下划线分隔,键不区分大小写。
示例:
WHOSTHERE__SPLASH__ENABLED=false- 禁用启动画面,等同于 YAML 配置中的splash.enabled: falseWHOSTHERE__SPLASH__DELAY=2s- 将启动画面延迟设置为 2 秒,等同于 YAML 配置中的splash.delay: 2sWHOSTHERE__SCAN_INTERVAL=30s- 将扫描间隔设置为 30 秒,等同于 YAML 配置中的scan_interval: 30sWHOSTHERE__TARGET_SUBNETS=10.0.0.0/24,10.0.1.0/24- 设置目标子网,等同于 YAML 配置中的target_subnets: ["10.0.0.0/24", "10.0.1.0/24"]WHOSTHERE__SCANNERS__MDNS__ENABLED=false- 禁用 mDNS 扫描器,等同于 YAML 配置中的scanners.mdns.enabled: falseWHOSTHERE__PORT_SCANNER__TCP=80,443,8080- 设置要扫描的自定义 TCP 端口,等同于 YAML 配置中的port_scanner.tcp: [80, 443, 8080]WHOSTHERE__THEME__NAME=cyberpunk- 将主题设置为 cyberpunk,等同于 YAML 配置中的theme.name: cyberpunk
守护进程模式 HTTP API
以守护进程模式运行 Whosthere 时,它会暴露一个非常简单的 HTTP API,包含以下端点:
| 方法 | 端点 | 描述 |
|---|---|---|
| GET | /devices | 获取所有已发现设备的列表 |
| GET | /device/{ip} | 获取特定设备的详情 |
| GET | /health | 健康检查 |