A comprehensive IoT device discovery and security analysis tool built with Python (Flask) and React.js.
- Network Range Scanning: Scan entire network ranges for IoT devices
- Single Device Analysis: Deep scan individual IP addresses
- IoT Device Detection: Identifies common IoT devices (Raspberry Pi, Arduino, ESP8266/ESP32, etc.)
- Vulnerability Assessment: Checks for common IoT security issues
- Service Enumeration: Discovers running services and their versions
- OS Detection: Identifies operating systems of discovered devices
- Web Interface: Clean, responsive React-based frontend
IOT_Scanner/
├── Flask_server/
│ ├── iot_scanner.py # Main Flask API with IoT scanning logic
│ ├── requirements.txt # Python dependencies
│ └── scanner.py # Basic scanner (legacy)
├── iot_ui/
│ ├── src/
│ │ └── app/
│ │ └── page.js # React frontend
│ └── package.json # Node.js dependencies
└── README.md
- Python 3.7+
- Node.js 14+
- nmap installed on your system
-
Navigate to the Flask server directory:
cd Flask_server -
Install Python dependencies:
pip install -r requirements.txt
-
Install nmap if not already installed:
- Ubuntu/Debian:
sudo apt-get install nmap - macOS:
brew install nmap - Windows: Download from nmap.org
- Ubuntu/Debian:
-
Run the Flask server:
python iot_scanner.py
The API will be available at http://localhost:5000
-
Navigate to the React app directory:
cd iot_ui -
Install Node.js dependencies:
npm install
-
Start the development server:
npm run dev
The web interface will be available at http://localhost:3000
Scan a network range for IoT devices.
Request:
{
"target": "192.168.1.0/24"
}Scan a single IP address.
Request:
{
"target": "192.168.1.100"
}Get API information and version.
- Start both the Flask backend and React frontend servers
- Open your browser to
http://localhost:3000 - Choose between scanning a network range or a single device
- Enter the target IP range or address
- Click "Start Scan" to begin discovery
- Review the results showing detected devices, their services, and potential vulnerabilities
The scanner identifies IoT devices based on:
- Port signatures: Common IoT service ports (1883, 8883, 8080, 8443, etc.)
- Service banners: Device-specific service responses
- Hostname patterns: Device naming conventions
- OS fingerprinting: Operating system characteristics
Supported device types include:
- Raspberry Pi
- Arduino Yun
- ESP8266/ESP32
- Amazon Echo/Alexa
- Google Home/Nest
- Philips Hue
- Samsung SmartThings
- TP-Link devices
- Xiaomi/Mi devices
The scanner checks for:
- Default credentials: Services with known default passwords
- Outdated services: Old versions of common services
- Unnecessary services: Exposed services that shouldn't be public
- Open ports: Port exposure analysis
Edit the iot_signatures dictionary in Flask_server/iot_scanner.py to add new device detection patterns:
'device_signatures': {
'New Device': ['keyword1', 'keyword2', 'keyword3'],
}Add new vulnerability checks in the check_vulnerabilities method of the IoTScanner class.
- nmap not found: Ensure nmap is installed and in your system PATH
- Permission denied: Run with appropriate permissions (may need sudo on Linux/macOS)
- Network unreachable: Check your network configuration and firewall settings
- CORS errors: Ensure the Flask server is running and accessible
- This tool is for educational and authorized network testing only
- Always obtain proper authorization before scanning networks you don't own
- Some features may require elevated privileges (sudo/administrator access)
This project is provided as-is for educational purposes.