Sheet B · Port & Service Scanners
Port and service scanners for checking your own machines
Once you know which devices exist, the next map layer is what each one offers to the rest of the network. Every listening port is a door: 445 for Windows file sharing, 3389 for Remote Desktop, 80 and 443 for a printer’s or camera’s web panel, 22 for SSH on a small server. A port scanner knocks on those doors on hosts you manage and reports which ones open, and the better tools go one step further and tell you which program is answering and which version it runs.
For the people we write for, the useful outcome is short and specific: a list of services per machine that you can hold up against what you expected. The reception PC should not be offering Remote Desktop to the whole office; the NAS should not have a forgotten FTP service switched on. We rate these tools on how clearly they present that list to someone who is not a security specialist. We also include Wireshark here even though it does not scan at all — it listens — because it is the tool you reach for when a port list alone does not explain what a device is doing. See our methodology for how each is reviewed.
6 port and service scanners side by side
Ordered by how readable the per-host service list is for a non-specialist; Wireshark is last because it answers a different question. Each row links to our full review; the vendor link opens the maker’s own site.
| Tool | Licence | Platforms | Key feature | Best for |
|---|---|---|---|---|
| Advanced Port ScannerFamatech | Freeware | Windows | Lists open ports per host with the service and version behind each | Checking which services your own machines expose |
| NmapNmap Project | NPSL | Windows, macOS, Linux, BSD | Service and OS fingerprinting, scriptable checks, Zenmap GUI | Admins who want precise, repeatable, scriptable audits |
| Angry IP ScannerAnton Keks | GPLv2 | Windows, macOS, Linux | Pluggable "fetchers" for ping, hostname, MAC and ports; CSV/XML export | Mixed-OS teams that want the same scanner on every laptop |
| SoftPerfect Network ScannerSoftPerfect | Commercial | Windows, macOS | Per-host queries over WMI, SNMP and the registry, plus IPv6 support | Technicians who need more than "it responds to ping" |
| Advanced IP ScannerFamatech | Freeware | Windows | One-click sweep with MAC vendor, shared folders and RDP/Radmin shortcuts | Windows offices that want a readable device list in minutes |
| WiresharkWireshark Foundation | GPLv2 | Windows, macOS, Linux | Passive capture and protocol decoding — it listens rather than probes | Confirming what a device actually sends on your own LAN |
Independent comparison — Scanlanmax is not any of these vendors, and none of them paid for placement. Licences and platforms checked against each vendor’s site at the date above.
How to choose
- Decide which ports matter before you scan
A full sweep of all 65,535 TCP ports on every host is slow and noisy. For a first pass, the few hundred most common ports cover file sharing, remote access, web panels and databases — the services that actually cause trouble in small offices.
- Prefer service names over bare numbers
"3389 open" means something to an administrator; "Remote Desktop (Microsoft Terminal Services)" means something to everyone. Tools that probe the service and print its name and version save a lot of lookup time.
- Remember UDP exists
DNS, DHCP, SNMP and many VoIP and IoT protocols use UDP, which simple scanners skip entirely. If you are checking a phone system or a managed switch, pick a tool that can include UDP, and accept that those scans take longer.
- Scan from where the risk is
Results depend on the vantage point. Scanning a server from the same subnet shows what colleagues can reach; scanning from the guest Wi-Fi shows what visitors can reach. Both views are useful, provided both segments are yours.
- Get permission in writing when it is not your box
Port scans against hosts owned by a hosting provider, a client or a neighbour’s network can breach acceptable-use terms. Keep scans to machines you administer, and keep a note of who authorised anything outside that.
Why a packet analyser sits in a scanner table
Scanners ask questions; a packet analyser overhears answers. When a port scan tells you a smart TV has port 8009 open, Wireshark on your own segment can show what that port is used for and how often the TV talks to the outside world. It is not a replacement for a scanner and it has a steeper learning curve, which is why it sits at the bottom of the table — but for patient troubleshooting on a network you run, it is the tool that turns a guess into evidence.
Vendor pages: Download for Windows · Download for Windows · Download for Windows · Download for Windows · Download for Windows · Download for Windows
Questions we get about port and service scanners
What is the difference between an IP scanner and a port scanner?
An IP scanner finds which addresses have a device behind them. A port scanner looks at one or more of those devices and lists which network services they offer. Many tools do a little of both; Nmap and Advanced Port Scanner lean towards the second job.
Is an open port a problem?
Not by itself. A file server is supposed to have 445 open, and a web panel on a printer needs 80 or 443. An open port becomes a problem when nobody expected it, when it is reachable from a segment it should not be, or when the service behind it is out of date.
How do I check which ports are open on my own PC?
Scan the PC from another machine on the same network to see what colleagues can reach, and compare with the local list from "netstat -ano" on Windows or "lsof -i -P" on macOS. Our walkthrough on checking open ports covers both steps.
Can a port scan slow the network down?
A sensible scan of a few hosts is negligible. Aggressive timing against many hosts can upset fragile devices such as old printers and some IoT gear, so start with the tool’s default or "polite" timing and scan outside busy hours.
Keep going
Disclosure: the vendor links on this page go straight to each vendor’s official site and earn us no commission. See our affiliate disclosure.