[Name]
tcpcat
[Version]
1.4.1 (git tag v1.4.1)
[Homepage]
https://tcpcat.io
Source: https://github.com/NycolazSec/tcpcat
[Download]
https://github.com/NycolazSec/tcpcat/archive/refs/tags/v1.4.1.tar.gz
Release page: https://github.com/NycolazSec/tcpcat/releases/tag/v1.4.1
[Author]
Nicolas Blondelle (NycolazSec)
[Licence]
Apache-2.0
[Description]
tcpcat is a network reconnaissance engine written in Go, intended for
authorized security assessments and network administration.
- TCP SYN / connect and UDP port scanning, with host discovery (ARP on the
local subnet, ping-based otherwise)
- Service and version detection (-sV), including TLS details
- OS fingerprinting (-O)
- CVE correlation against an embedded offline database, Google OSV or the
Vulners API
- Machine-readable reports: JSON, SARIF, an append-only JSONL audit log,
and baseline comparison (new ports, changed services, new CVEs)
- Scope file (--scope-file) and a conservative "safe-production" profile
for approved engagements
On Linux, an optional eBPF/AF_XDP engine (--ebpf) assembles an XDP program
at runtime and redirects only the replies to tcpcat's own probes into
AF_XDP sockets; all other traffic on the interface goes through the normal
kernel stack untouched.
Benchmark (hyperfine, 3 runs, SYN scan of all 65,535 ports on 2 hosts,
same interface, 25,000 packets/s target rate for every tool):
tcpcat --ebpf 4.466 s ± 0.744
nmap 11.723 s ± 0.503
naabu 20.945 s ± 0.181
[Dependencies]
Build: Go >= 1.26 (Kali's golang-any 2:1.26~1 works), no cgo, no libpcap.
Go module path: github.com/NycolazSec/tcpcat
Runtime: iputils-ping (ping-based host discovery fallback). Raw-socket
scans need root or CAP_NET_RAW; --ebpf needs Linux >= 5.8 and root.
[Similar tools]
nmap, masscan, naabu, rustscan, zmap
[Activity]
Started 2026-09-10 and actively developed: 105 commits and 9 tagged
releases (v1.0.0 to v1.4.1). CI runs go test -race, golangci-lint, gosec
and govulncheck. OpenSSF Best Practices badge:
https://www.bestpractices.dev/projects/14561
[How to install]
The source tree ships a debian/ directory modeled on Kali's packaging of
naabu (dh-golang, modules fetched at build time):
dpkg-buildpackage -us -uc
Or directly:
go build -trimpath -ldflags "-X main.version=1.4.1" -o tcpcat ./cmd/tcpcat
[How to use]
tcpcat --help
sudo tcpcat -sS --top-ports 1000 192.168.1.0/24
sudo tcpcat -sS -sV -O -p 22,80,443 10.0.0.5 -j report.json --sarif report.sarif
sudo tcpcat --profile safe-production --scope-file scope.txt -Pn -sT -sV -p 443 --audit-log audit.jsonl 10.0.0.5
[Packaged]
Yes, upstream provides Debian packaging (debian/, version 1.4.1-0kali1).
Built in a kalilinux/kali-rolling container: builds and installs cleanly,
the Go test suite passes during the build, lintian reports no errors or
warnings, and it includes a tcpcat(1) man page and an autopkgtest.
Upstream also publishes .deb and .rpm packages for amd64 and arm64 with
every GitHub release. |