<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: tcpcat</title>
    <description>The latest articles on DEV Community by tcpcat (@tcpcat).</description>
    <link>https://dev.to/tcpcat</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4155716%2F92d366ba-3085-4e6c-9fcd-f88832774eae.jpg</url>
      <title>DEV Community: tcpcat</title>
      <link>https://dev.to/tcpcat</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tcpcat"/>
    <language>en</language>
    <item>
      <title>tcpcat: an open-source network recon engine in Go with eBPF/AF_XDP and WASM detection</title>
      <dc:creator>tcpcat</dc:creator>
      <pubDate>Thu, 01 Oct 2026 19:37:25 +0000</pubDate>
      <link>https://dev.to/tcpcat/tcpcat-an-open-source-network-recon-engine-in-go-with-ebpfafxdp-and-wasm-detection-4i31</link>
      <guid>https://dev.to/tcpcat/tcpcat-an-open-source-network-recon-engine-in-go-with-ebpfafxdp-and-wasm-detection-4i31</guid>
      <description>&lt;p&gt;I've been building &lt;strong&gt;tcpcat&lt;/strong&gt;, a network reconnaissance and vulnerability-intelligence engine written in Go. It's meant for learning, network administration and &lt;strong&gt;authorized&lt;/strong&gt; security testing, and it's free and open source under the AGPL-3.0.&lt;/p&gt;

&lt;p&gt;👉 &lt;strong&gt;Repo:&lt;/strong&gt; &lt;a href="https://github.com/NycolazSec/tcpcat" rel="noopener noreferrer"&gt;https://github.com/NycolazSec/tcpcat&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why I built it
&lt;/h2&gt;

&lt;p&gt;I wanted one tool that could enumerate a network, fingerprint what it finds, correlate it with known CVEs, and let me check whether my IDS/IPS actually sees what it should, without stitching together five different programs.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;L2–L7 reconnaissance&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Multi-protocol port enumeration (TCP, UDP, ICMP)&lt;/li&gt;
&lt;li&gt;Service topology mapping with version fingerprinting&lt;/li&gt;
&lt;li&gt;Asynchronous DNS / mDNS / NetBIOS discovery&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;CVE correlation&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Vulners API, Google OSV, or an offline database&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Assessment controls for testing monitoring visibility&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Timing jitter, IPv4 fragmentation, decoy traffic, TCP/UDP window tuning, source-port selection&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Programmable detection with WebAssembly&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Write detection rules and protocol dissectors in Rust, C, Go or AssemblyScript&lt;/li&gt;
&lt;li&gt;Scripts run in a sandbox, so a bad plugin can't take the engine down&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Performance
&lt;/h2&gt;

&lt;p&gt;On Linux (kernel 5.8+), tcpcat can use &lt;strong&gt;eBPF / AF_XDP&lt;/strong&gt; to do packet I/O at the driver level and bypass the socket layer. That's what makes high-throughput scanning possible (around 1M packets per second per core). It's optional, and tcpcat works without it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Getting started
&lt;/h2&gt;

&lt;p&gt;Requirements: Go 1.26+. Pre-built packages are available for macOS (&lt;code&gt;.dmg&lt;/code&gt;) and Debian/Ubuntu (&lt;code&gt;.deb&lt;/code&gt;) on the &lt;a href="https://github.com/NycolazSec/tcpcat/releases" rel="noopener noreferrer"&gt;releases page&lt;/a&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/NycolazSec/tcpcat.git
&lt;span class="nb"&gt;cd &lt;/span&gt;tcpcat
make
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Licensing
&lt;/h2&gt;

&lt;p&gt;tcpcat is dual-licensed: &lt;strong&gt;AGPL-3.0&lt;/strong&gt; for open-source use, and a commercial (OEM) license if you want to embed it in a proprietary product or hosted service. There is no hosted scanning service and no paid support.&lt;/p&gt;

&lt;h2&gt;
  
  
  Responsible use
&lt;/h2&gt;

&lt;p&gt;Only scan networks you own or have written permission to test.&lt;/p&gt;

&lt;h2&gt;
  
  
  Feedback welcome
&lt;/h2&gt;

&lt;p&gt;I'd especially like feedback on the WASM plugin API and on which detection rules would be most useful to ship by default. Issues, stars and PRs are all appreciated: &lt;a href="https://github.com/NycolazSec/tcpcat" rel="noopener noreferrer"&gt;https://github.com/NycolazSec/tcpcat&lt;/a&gt;&lt;/p&gt;

</description>
      <category>go</category>
      <category>security</category>
      <category>networking</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
