Quick subnet sweeps with pluggable fetchers and simple exports
Angry IP Scanner is a small, quick IP address scanner that has been in continuous use for well over two decades. It is written in Java, which is why one download runs on Windows, macOS and Linux, and the Windows setup bundles the runtime so nothing else has to be installed first. Its job is deliberately narrower than a full network scanner's: you give it a range of addresses, it works through them in parallel and fills a table with whatever it found. That focus is exactly why it stays useful. Starting a scan takes seconds, the interface needs no manual, and the results are easy to read and to export.
How a scan is set up
The usual input is a range such as an address with a /24 suffix, a hyphenated span of addresses, or a list read from a file. Before starting, you choose which fetchers to run. A fetcher is the plug-in that performs one kind of check against a host: sending a ping, testing a set of TCP ports, resolving a hostname, reading the MAC address, looking up the vendor behind that address, or asking for basic NetBIOS information. Only the fetchers you enable will run, and each one costs time on every address, so a scan of a large range with many fetchers takes far longer than a ping sweep. Results appear in a sortable table, and exporting to CSV, TXT or XML produces a file that is straightforward to process elsewhere. The project also documents a command-line mode with fetcher selection and output file options, which is how many administrators fold the scanner into scheduled inventory work.
Practical limits worth knowing in advance
Angry IP Scanner answers one question well - is something there, and is a given port open - and it stops short of everything after that. It does not identify which service or version is listening behind an open port, does not fingerprint operating systems, and does not test for vulnerabilities. A port is reported as open, and no further inference should be drawn from that. The ping fetcher is also easy to misread: a host that blocks ICMP will look dead even while it is running and serving traffic, which is why enabling a port check alongside ping gives a more honest picture. MAC address and vendor data only mean something on the local network segment, because a router rewrites the layer-two header as packets cross it. The scan is multithreaded and can be aggressive; on a fragile link or an old device, lowering the thread count avoids causing the very outage you were trying to rule out. The Windows package needs no separate Java install, but it does place a runtime on the machine.
Scanning networks you do not own
The tool is lawful to use in many contexts and unlawful in others. Sweeping an address range that belongs to someone else, or to an employer without authorisation, may breach computer misuse law and provider terms even when the scan itself does no harm. Keep ranges inside your own area of responsibility.
Where another tool is the better choice
If you need service banners, version detection, operating system guesses or scripted checks, Nmap is the right tool and this scanner will not substitute for it. If you need continuous discovery with history and alerting, an asset inventory platform serves better. For the everyday question of what is currently answering on a subnet, this scanner remains one of the fastest ways to find out.
- Best for
- Anyone who needs a fast, no-fuss sweep of a subnet: home users, support technicians and administrators checking what addresses are answering and which ports are open.
- Good to know
- It reports reachability and open ports only, never services or vulnerabilities. ICMP-blocking hosts can look dead, MAC vendor data is meaningful only on the local segment, and the Windows setup bundles its own Java runtime.
Angry IP Scanner turns a range of addresses into a readable table of live hosts and open ports.
How to get started
- Run the official setup, which includes the Java runtime it needs, and launch the application.
- Enter the range you are responsible for, either as a network prefix, a hyphenated span or a list loaded from a file.
- Choose the fetchers for this scan. Ping alone is fastest; adding a port check catches hosts that ignore ICMP, and MAC or hostname fetchers cost extra time per address.
- Start the scan, sort the results by the column that matters, then export to CSV, TXT or XML if another tool or a spreadsheet needs the data.
Lower the thread count on unreliable links, and keep large ranges for off-peak hours.
Questions & answers
Is Angry IP Scanner free?
Yes. It is open-source software released under the GNU GPL version 2 or later, and the official builds for Windows, macOS and Linux are free to download and use.
Does it identify the services running on open ports?
No. It reports that a port is open or closed. For banners, version detection and operating system guesses you need a different tool, such as Nmap.
Why do some live devices show as dead?
Because they ignore ICMP echo requests. Enable a port fetcher as well, and hosts that quietly serve traffic will appear even when they never answer a ping.