View Issue Details

IDProjectCategoryView StatusLast Update
0009871Kali LinuxNew Tool Requestspublic2026-09-28 19:31
Reporternycolazsec Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
Summary0009871: tcpcat, fast network scanner with an eBPF/AF_XDP engine and CVE correlation
Description

[Name]
tcpcat

[Version]
1.4.1 (git tag v1.4.1)

[Homepage]
https://tcpcat.io
Source: https://github.com/NycolazSec/tcpcat

[Download]
https://github.com/NycolazSec/tcpcat/archive/refs/tags/v1.4.1.tar.gz
Release page: https://github.com/NycolazSec/tcpcat/releases/tag/v1.4.1

[Author]
Nicolas Blondelle (NycolazSec)

[Licence]
Apache-2.0

[Description]
tcpcat is a network reconnaissance engine written in Go, intended for
authorized security assessments and network administration.

  • TCP SYN / connect and UDP port scanning, with host discovery (ARP on the
    local subnet, ping-based otherwise)
  • Service and version detection (-sV), including TLS details
  • OS fingerprinting (-O)
  • CVE correlation against an embedded offline database, Google OSV or the
    Vulners API
  • Machine-readable reports: JSON, SARIF, an append-only JSONL audit log,
    and baseline comparison (new ports, changed services, new CVEs)
  • Scope file (--scope-file) and a conservative "safe-production" profile
    for approved engagements

On Linux, an optional eBPF/AF_XDP engine (--ebpf) assembles an XDP program
at runtime and redirects only the replies to tcpcat's own probes into
AF_XDP sockets; all other traffic on the interface goes through the normal
kernel stack untouched.

Benchmark (hyperfine, 3 runs, SYN scan of all 65,535 ports on 2 hosts,
same interface, 25,000 packets/s target rate for every tool):
tcpcat --ebpf 4.466 s ± 0.744
nmap 11.723 s ± 0.503
naabu 20.945 s ± 0.181

[Dependencies]
Build: Go >= 1.26 (Kali's golang-any 2:1.26~1 works), no cgo, no libpcap.
Go module path: github.com/NycolazSec/tcpcat
Runtime: iputils-ping (ping-based host discovery fallback). Raw-socket
scans need root or CAP_NET_RAW; --ebpf needs Linux >= 5.8 and root.

[Similar tools]
nmap, masscan, naabu, rustscan, zmap

[Activity]
Started 2026-09-10 and actively developed: 105 commits and 9 tagged
releases (v1.0.0 to v1.4.1). CI runs go test -race, golangci-lint, gosec
and govulncheck. OpenSSF Best Practices badge:
https://www.bestpractices.dev/projects/14561

[How to install]
The source tree ships a debian/ directory modeled on Kali's packaging of
naabu (dh-golang, modules fetched at build time):
dpkg-buildpackage -us -uc
Or directly:
go build -trimpath -ldflags "-X main.version=1.4.1" -o tcpcat ./cmd/tcpcat

[How to use]
tcpcat --help
sudo tcpcat -sS --top-ports 1000 192.168.1.0/24
sudo tcpcat -sS -sV -O -p 22,80,443 10.0.0.5 -j report.json --sarif report.sarif
sudo tcpcat --profile safe-production --scope-file scope.txt -Pn -sT -sV -p 443 --audit-log audit.jsonl 10.0.0.5

[Packaged]
Yes, upstream provides Debian packaging (debian/, version 1.4.1-0kali1).
Built in a kalilinux/kali-rolling container: builds and installs cleanly,
the Go test suite passes during the build, lintian reports no errors or
warnings, and it includes a tcpcat(1) man page and an autopkgtest.
Upstream also publishes .deb and .rpm packages for amd64 and arm64 with
every GitHub release.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2026-09-28 19:31 nycolazsec New Issue