tcpsweep
A netcat-style TCP connect sweep in a single, dependency-free Python file.
tcpsweep sends the same probe as nc -z (a full TCP connect) to every
host/port in a target spec and reports which ports are open. It uses the
standard library only, so it can be dropped onto any box with a Python 3
interpreter and run directly (./tcpsweep.py ...) or as a module
(python3 -m tcpsweep ...).
Discovered open ports stream to stdout (one IP PORT line each) so the
tool composes in a pipeline; progress and the summary go to stderr.
Results are also written to NAME.json and NAME.gnmap plus a resumable
NAME.state.json — all written atomically and owner-readable only (0600),
since a scan result is sensitive reconnaissance data.
Authorized use only. Only scan hosts and networks you own or have explicit permission to test.
Install
pipx install tcpsweep # isolated, recommended for a CLI tool
pip install tcpsweep # or a plain pip install
Both provide a tcpsweep command on your PATH. The tool has no third-party
dependencies, so you can also just copy tcpsweep.py onto a host and run it.
Requirements
- Python 3.8+ (standard library only — no third-party packages)
Usage
tcpsweep 192.168.1.1 22 80 443
tcpsweep 192.168.1.0/24 -p 22,80,443 -t 16
tcpsweep 10.0.0.{1-10,254} -p 1-1024 -r -o office
tcpsweep 192.168.1.1 -p 1-65535 -w 2 -P 0.2 # rate-limited, 0.2s gap
tcpsweep 10.0.0.0/24 -p 22 -b # grab banners
Run tcpsweep --help for the full option list, including target selection
(CIDR / dash ranges / brace notation / -iL target files / --exclude),
threading, rate limiting, link-health auto-pause, and the various output
formats (-oJ / -oX / -oT / -oC / -oA).
A note on -w 0
-w 0 does not mean "no timeout". A zero timeout puts the socket into
non-blocking mode, so every connect fails instantly and every port — including
live listeners — is reported filtered. tcpsweep warns and falls back to the
6s default rather than scanning blind. Pass a real value (fractions are fine:
-w 0.5) to choose your own.
Running through proxychains
A TCP connect scan is exactly the kind of scan that survives a SOCKS proxy, so
proxychains4 tcpsweep ... works — with two caveats the tool now warns about.
proxychains4 -q tcpsweep 10.0.0.0/24 -p 22,80,443 -t 4
-w/--timeout is advisory. proxychains performs the SOCKS handshake inside
its hooked connect(), so its tcp_connect_time_out and tcp_read_time_out
(in /etc/proxychains4.conf, milliseconds) decide how long a dead target
costs. Set them at or below your -w, or a silently-dropped port stalls for
their duration instead of yours.
closed is inferred from timing, not just errno. When a target is dropped,
proxychains gives up on its own timeout and reports ECONNREFUSED — identical,
by errno, to a real refusal. tcpsweep therefore treats a refusal that took
longer than the whole connect budget as filtered rather than closed, since
a RST arrives in about one round trip. Without that, firewalled ports get
recorded as definitively closed, which is the worst error a port scanner can
make.
Two more things worth knowing:
- With
proxy_dnsenabled, a hostname target resolves to a synthetic224.0.0.xplaceholder. The scan reaches the right host, but results are labelled with that placeholder — scan a literal IP if the report needs real addresses.tcpsweepwarns when it sees one. - Keep
-tlow (1–4). proxychains' hooks serialise on a single chain, so more threads add contention rather than speed.
Output files
By default the scanner writes working files named after the target (or the
-o NAME base):
| File | Contents |
|---|---|
NAME.json |
Structured results for this scan |
NAME.gnmap |
Greppable, nmap-style summary |
NAME.state.json |
Resume state for an interrupted scan |
These files hold reconnaissance data and are excluded from version control via
.gitignore.
Only an unfinished scan is resumed. If a previous run completed, its state
file is left in place but not replayed — every port is probed again, and a
warning says so. Resuming a finished scan would report ports as open without
sending a packet, which is indistinguishable from a live result. A scan that
was Ctrl+C'd, crashed, or was killed still resumes; --fresh discards the
state file entirely.
Every reported figure — the .json, the .gnmap, the exported reports and
the summary counts — covers only the hosts and ports of the run that produced
it, even when a state file carries results from a wider earlier scan.
Development
Run the test suite with:
python3 -m pytest test_scan.py -q # or: python3 -m unittest test_scan
Metadata
Release files for tcpsweep 0.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tcpsweep-0.2.1.tar.gz | 40.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tcpsweep-0.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 68.9 kB
Release files / tcpsweep-0.2.1.tar.gz
| Download URL | tcpsweep-0.2.1.tar.gz |
|---|---|
| Size | 40.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
01516bd1e8ade625502f31bdf120689ceb39780f0f308d92014b68956c9e89df
|
|
BLAKE2b-256 checksum How to use checksums |
eead60529748a56a0b92c11c843831d1b7bddcbb6f826da5dbdc84bc04e0cd5e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 24, 2026.
Transparency logRelease files / tcpsweep-0.2.1-py3-none-any.whl
| Download URL | tcpsweep-0.2.1-py3-none-any.whl |
|---|---|
| Size | 28.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
02f18c478fe90f83a8efe258fa53dd0eb05e2e802b46c1c45019d44c1797512a
|
|
BLAKE2b-256 checksum How to use checksums |
88d12a006dd633aa5672a78466ba9ab3fd45b23c1cb6d815fd71bc087c9f508c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 24, 2026.
Transparency log