resources
ThopterIoT: free IoT and camera discovery for Windows
ThopterIoT is a free, open-source Windows tool that finds the IoT devices and IP cameras on your local network: IP address, MAC and vendor, a device type and model guess, hostnames, and the ports each device answers on. It installs no driver, needs no admin rights, sends no telemetry, and the scan never leaves your machine.
Windows 10 and 11. Apache License 2.0. No account, no sign-up.
discovery
One scan, the whole subnet, identified.
Every device with an address
A one-shot sweep of the local subnet that comes back with the IP and MAC of every responding device, with no capture driver and no elevation. Randomized and locally administered MACs are flagged for what they are.
Vendor, type, and model
The vendor behind every MAC, resolved offline against the embedded IEEE registry, fused with what each device advertises about itself into a type and model guess. Cameras, printers, door controllers, and the things nobody remembers installing.
What each device speaks
The standard discovery protocols a device already answers on the LAN, plus a light banner check on open ports and a hostname wherever the device exposes one. Nothing is probed beyond what any neighbor on the network could ask.
A grid you can hand to someone
A live device grid: IP, MAC, vendor, model, hostname, open ports, and how each device was discovered. Copy an address, open a device in the browser, or export the whole run as CSV or JSON. A headless scan mode covers scripting.
conduct
Built to be run on other people's networks.
What it never does
It never logs in to anything. It never touches video: no streams, no snapshots, no frames. It scans once and stops; nothing keeps watching the network afterward. There is no telemetry and no call-home. Every request it makes is unauthenticated and standard, the kind of thing any device on the LAN already answers.
How you can be sure
The scanner is fully open source under Apache 2.0, so the claim above is checkable, not marketing. The repository holds no cloud or monitoring code at all, and continuous integration enforces that wall on every commit. What the tool sends is in the code, and the code is public.
free and paid
The free tool is the whole tool.
Free: the scanner
Everything on this page above the wall. No locked columns, no trial clock, no account. It is the tool, not a demo of one, and it stays that way: the free build is where new discovery capability lands first, in the open, under Apache 2.0.
Paid: what those devices mean
A scan tells you what is on the network. The paid version answers the question that raises: is any of it a problem? It cross-references your findings against published camera CVEs, with the same in-the-wild flag as our camera CVE tracker, and against NDAA Section 889 restrictions, as in the NDAA camera checker. From there it can continue into ongoing fleet monitoring through the MentatNOC platform. It monitors device health, not video.
questions
Quick answers.
Is ThopterIoT free?
Yes. ThopterIoT is free and open source under the Apache 2.0 license. The scanner is the complete tool, not a trial: every column, every discovery protocol, and CSV and JSON export ship in the free build, and no account is required. A separate paid version adds CVE matching, NDAA Section 889 flags, and ongoing monitoring through MentatNOC.
Does ThopterIoT need admin rights or a capture driver?
No. It runs as a normal user on Windows 10 and 11 with no packet capture driver and no elevation. Every request it makes is unauthenticated and standard, the kind of thing any device on the network already answers.
Does the free ThopterIoT scanner send any data off my machine?
No. The free tool sends nothing off your machine: no telemetry, no call-home. It never logs in to a device and it never touches video. A scan runs once, stops, and the results stay local unless you export them yourself. The repository holds no cloud code, and continuous integration enforces that on every commit.
What does the paid version of ThopterIoT add?
The paid version cross-references a scan against published camera CVEs, including whether CISA lists them as exploited in the wild, and against NDAA Section 889 restrictions, and can continue into ongoing fleet monitoring through MentatNOC. It monitors device health, not video. Contact us to talk it through.
get it
Point it at a subnet this afternoon.
The free scanner runs with no driver, no admin rights, and no account. When you want the CVE and NDAA answers on top, we are one message away.