A private, local-first network intelligence and asset ledger desktop app for Windows, Linux, and macOS.
English • العربية
⬇️ Download Windows (.exe) • 📸 Screenshots & Tour • ⚡ How It Works • 🛠️ Technical Architecture • 🌐 GitHub Wiki
"Scanning tells you what's there now.
Inventory tells you what changed."
When you connect to Wi-Fi at home, in the office, or at a client site, you often want answers to simple, critical questions:
- What devices are connected right now?
- What is that mystery IP address on my subnet?
- Who joined the network today? Did my server reboot?
- Did my phone get assigned a new IP address?
Traditional tools (like Advanced IP Scanner or Angry IP Scanner) are momentary utilities: they perform a single sweep, show a plain table, and discard everything the moment you close them.
NETWATCH is different.
Scanning is just the ingestion sensor. Behind the scenes, NETWATCH maintains a persistent local SQLite asset ledger. It remembers every host that ever touched your subnet, tracks joins and departures, alerts you to IP changes, and lets you organize your network into a clean, searchable inventory — 100% offline, with zero cloud and zero telemetry.
Discover every active computer, phone, printer, smart TV, and IoT sensor on your /24 subnet in seconds.
NETWATCH uses unprivileged user-mode operating system APIs — no Administrator rights, no UAC popups, and no third-party packet capture drivers (WinPcap/Npcap) required.
Instantly identifies manufacturers (Apple, Intel, Samsung, Espressif, Raspberry Pi, ZTE) using an embedded, offline IEEE OUI database. Your hardware MAC addresses are never sent to external lookup APIs.
Give your hardware friendly names (e.g., "Living Room Apple TV", "Proxmox Lab 01"), select custom device categories, and choose matching icons (Computer, Phone, Server, Router, IoT, Camera, Printer, Game Console). Your customizations are saved permanently and are never overwritten by rescans.
Modern smartphones (iOS, Android) and Windows 10/11 rotate their Wi-Fi MAC addresses for privacy. NETWATCH automatically flags "Private MAC" addresses and provides a 1-click Device Merge tool to unify fragmented device histories under one record.
Organize your devices into trust levels:
Known: Approved assets (your workstations, family phones, home servers).Guest: Temporary visitors.Unknown: Newly discovered or unrecognized hardware that needs inspection.
Inspect your local network hierarchy: WAN Internet gateway, default router, broadcast domain, and connected endpoints. Automatically resolves your network's external public IP over lightweight STUN (UDP) without cloud tracking.
Low-power Wi-Fi devices sleep frequently to save battery. NETWATCH only marks a device offline after consecutive missed sweeps, preventing annoying false disconnect alarms.
- Live ICMP Ping: Real-time round-trip latency graph and packet loss measurement.
- Wake-on-LAN (WoL): Send magic broadcast packets to wake sleeping PCs on your LAN.
- Port Scanner: Check open TCP service ports (HTTP, SSH, SMB, RDP, RTSP).
- Desktop Toast Notifications: Optional Windows notifications when unknown devices appear or gateways change.
| Role | How NETWATCH Helps You |
|---|---|
| 🏠 Home Lab & Self-Hosters | Track your Raspberry Pis, NAS drives, Proxmox clusters, and ESP32 home automation sensors without setting up heavy enterprise agents. |
| 💻 DevOps & Remote Workers | Instantly audit client networks or home office LANs. Verify IP allocations, test gateway latency, and check open service ports. |
| 🛡️ Privacy Advocates | Audit every device in your home without trusting third-party cloud scanners or sending your home network topology to remote servers. |
| 🏢 Small Office & IT Techs | Know immediately when an unrecognized laptop plugs into the office switch, spot IP conflicts, and maintain an up-to-date asset ledger. |
Mobile-First Responsive Design: Seamlessly inspect your network from phones, tablets, or narrow laptop viewports.
- Download
netwatch.exefrom the Latest Release. - (Optional & Recommended) Verify the SHA-256 cryptographic hash against the release notes:
Get-FileHash .\netwatch.exe -Algorithm SHA256
- Double-click to run:
- No installation needed (portable single-file executable).
- No administrator elevation required (unprivileged user mode).
- Unsigned binary model: On initial launch, Windows SmartScreen may display "Unknown Publisher / Windows protected your PC". Click "More info" -> "Run anyway".
- Your data is stored locally in
%LOCALAPPDATA%\NetWatch\data\network.db.
For headless machines, continuous background monitoring, or Linux servers:
# Clone the repository
git clone https://github.com/alwkala/NETWATCH.git && cd NETWATCH
# Run the standalone headless daemon
go run ./cmd/netwatchdNETWATCH was built around a non-negotiable philosophy: "Your network data belongs to you."
- Zero Cloud Uploads: Network mappings, IP addresses, and MAC addresses never leave your machine.
- Zero Telemetry: No analytics, no tracking beacons, no accounts.
- Local SQLite Storage: All history and settings are stored in an open SQLite database on your local disk.
- Air-Gapped Typography: All fonts (Plus Jakarta Sans & JetBrains Mono) are bundled inside the app. No calls to Google Fonts or remote CDNs.
- Automated CI Security Gate: An automated CI test inspects every commit to ensure no external HTTP requests can be introduced.
Looking for deep technical architecture, threat models, or contributor runbooks?
- Technical Architecture Guide — Comprehensive guide to the Go engine, React 19 UI, and IPC.
- GitHub Wiki — Full wiki documentation, subsystem deep dives, and operational runbooks.
- Public Roadmap (M1–M7) — Milestone progress and future capabilities.
- Threat Model (STRIDE) — Security boundaries, trust domains, and threat analysis.
- Release Changelog — Detailed historical release notes following Keep a Changelog.
- Security Policy — Vulnerability reporting and responsible disclosure policy.
- Contributing Guidelines — How to contribute code, documentation, and design.
NETWATCH is dual-licensed under both the MIT License and the Apache License 2.0.
You may choose either license at your option.



