RHIZOMON
A live 3D map of every device on your local network. One small program, opened in your browser. Nothing leaves your machine.
Download
Latest release: v0.1.1 · Try the demo in your browser (synthetic network, nothing is scanned) · Mirror of the latest release on this site
Checksums: SHA256SUMS · All releases · Source
Status: macOS is tested on a real network. The Linux and Windows builds compile and pass the test suite in CI but are new and have not yet been run against a real network by the maintainers. Reports welcome.
Run it
Then open http://127.0.0.1:7878 in your browser. Stop it with Ctrl-C.
macOS
tar -xzf rhizomon-*-apple-darwin.tar.gz cd rhizomon-*-apple-darwin chmod +x rhizomon xattr -d com.apple.quarantine rhizomon # the binary is not notarised ./rhizomon
Allow Local Network access for your terminal when macOS asks; without it the scan sees only the router.
Linux
tar -xzf rhizomon-*-unknown-linux-gnu.tar.gz cd rhizomon-*-unknown-linux-gnu chmod +x rhizomon ./rhizomon
Needs glibc 2.35 or newer. If unprivileged ping is disabled on your system (net.ipv4.ping_group_range), the system ping is used instead.
Windows (PowerShell)
Expand-Archive rhizomon-*-pc-windows-msvc.zip -DestinationPath . cd rhizomon-*-pc-windows-msvc .\rhizomon.exe
The binary is not code-signed, so SmartScreen may show "Windows protected your PC": choose More info, then Run anyway. Allow it on private networks if Windows Firewall asks.
From source
Needs git and a Rust toolchain (1.85 or newer). Install Rust with rustup; on Windows it also asks for the Visual Studio C++ build tools, and on Linux you need a C compiler (build-essential or equivalent) for the bundled SQLite.
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh # macOS / Linux; Windows: run rustup-init.exe git clone https://github.com/prix0007/rhizomon.git cd rhizomon cargo run --release
The first build takes a few minutes. The UI is embedded in the binary, so no Node or npm is needed.
What it does
- Finds devices on your subnet and shows vendor, name and type where they can be learned.
- Updates live as devices join and leave, and remembers when each was first and last seen.
- Listens on 127.0.0.1 only. No cloud service, no account, no telemetry.
Only scan networks you own or are allowed to scan.
Security
Rhizomon listens on 127.0.0.1 only, makes no outbound internet requests, and renders every string from the network as plain text. The code is reviewed against that model, and the findings are published in full rather than summarised:
- Security review, October 2026: scope, threat model, every finding with its severity and status, and the controls verified.
- Security model and known limitations in the README.
- Found something? Open an issue, or use GitHub's private vulnerability reporting on the repository if it is sensitive.
Buy me a coffee
Rhizomon is free, open-source software built by one maintainer. If it helps you, a voluntary donation in ETH on Ethereum mainnet goes toward hosting and development.
0xfb4172e26AC8735C06656f1df14151cFe8441481
- Send only ETH on Ethereum mainnet. Tokens or other networks sent here may be lost.
- The same address is in the GitHub README; check it matches character for character before sending.
- Donations are non-refundable and come with no perks, goods or services. There is no company behind the project, so no tax receipts.
- Not using a wallet? Starring the repository or reporting a bug helps too.