DEV Community

Cover image for tcpcat: an open-source network recon engine in Go with eBPF/AF_XDP and WASM detection
tcpcat
tcpcat

Posted on

tcpcat: an open-source network recon engine in Go with eBPF/AF_XDP and WASM detection

I've been building tcpcat, a network reconnaissance and vulnerability-intelligence engine written in Go. It's meant for learning, network administration and authorized security testing, and it's free and open source under the AGPL-3.0.

👉 Repo: https://github.com/NycolazSec/tcpcat

Why I built it

I wanted one tool that could enumerate a network, fingerprint what it finds, correlate it with known CVEs, and let me check whether my IDS/IPS actually sees what it should, without stitching together five different programs.

What it does

L2–L7 reconnaissance

  • Multi-protocol port enumeration (TCP, UDP, ICMP)
  • Service topology mapping with version fingerprinting
  • Asynchronous DNS / mDNS / NetBIOS discovery

CVE correlation

  • Vulners API, Google OSV, or an offline database

Assessment controls for testing monitoring visibility

  • Timing jitter, IPv4 fragmentation, decoy traffic, TCP/UDP window tuning, source-port selection

Programmable detection with WebAssembly

  • Write detection rules and protocol dissectors in Rust, C, Go or AssemblyScript
  • Scripts run in a sandbox, so a bad plugin can't take the engine down

Performance

On Linux (kernel 5.8+), tcpcat can use eBPF / AF_XDP to do packet I/O at the driver level and bypass the socket layer. That's what makes high-throughput scanning possible (around 1M packets per second per core). It's optional, and tcpcat works without it.

Getting started

Requirements: Go 1.26+. Pre-built packages are available for macOS (.dmg) and Debian/Ubuntu (.deb) on the releases page.

git clone https://github.com/NycolazSec/tcpcat.git
cd tcpcat
make
Enter fullscreen mode Exit fullscreen mode

Licensing

tcpcat is dual-licensed: AGPL-3.0 for open-source use, and a commercial (OEM) license if you want to embed it in a proprietary product or hosted service. There is no hosted scanning service and no paid support.

Responsible use

Only scan networks you own or have written permission to test.

Feedback welcome

I'd especially like feedback on the WASM plugin API and on which detection rules would be most useful to ship by default. Issues, stars and PRs are all appreciated: https://github.com/NycolazSec/tcpcat

Top comments (0)