TechScan365IPAM, DHCP & subnet tools, reviewed

Safe sourcing

Where to get each tool

TechScan365 hosts no software and never will. This page names the genuine source of every product we cover and shows how to verify what you receive before it touches a server.

Entry checked against the record · initialled by Husanjon Ruzaliev (editor)

Why there are no copies here

IPAM and discovery tools end up on servers with broad network reach and, often, credentials for DHCP, DNS and SNMP. That makes a tampered copy far more dangerous than a tampered desktop utility. Look-alike sites buy ads against popular tool names and repackage genuine software with extras, so the rule is simple: take every product from the vendor or project that publishes it, and verify it before deployment. We cannot make a copy more trustworthy than the original, so we do not offer one — every link below goes to the maker’s own page.

Official sources for all 9 tools

ToolPublished byLicenceOfficial siteWhat to check
phpIPAMphpIPAM projectGPLv3Visit phpipam.net Self-hosted PHP app. Take a tagged release from the project’s GitHub repository linked on phpipam.net, and check the tag before deploying.
NetBoxNetBox LabsApache 2.0 + paidVisit netboxlabs.com Community edition: tagged releases from the netbox-community GitHub repository or the project’s official Docker image. Cloud and Enterprise: through a NetBox Labs account.
GestioIPGestioIPGPLv3Visit gestioip.net Perl web app. Use the release linked from gestioip.net (hosted on the project’s SourceForge page) or the Docker Compose project the site links to.
SolarWinds IP Address ManagerSolarWindsVisit solarwinds.com Start from the trial form on solarwinds.com; licensed customers use the SolarWinds customer portal. Windows files should be signed by SolarWinds.
ManageEngine OpUtilsManageEngine (Zoho Corp.)Free edition + paidVisit manageengine.com Obtain the Windows or Linux build from manageengine.com only. Windows files should carry a Zoho Corporation signature.
MicetroBlueCat (formerly Men & Mice)Visit bluecatnetworks.com No public self-service copy: request a trial or quote through bluecatnetworks.com and use the links BlueCat provides.
Angry IP ScannerAnton KeksGPLv2Visit angryip.org Follow the links on angryip.org to the project’s own GitHub releases; the Windows and macOS packages bundle Java.
LizardSystems Network ScannerLizardSystemsFree personal · paid businessVisit lizardsystems.com Windows only. The vendor lists a SHA-256 for the current build on its product page; compare it with Get-FileHash before running.
LizardSystems LanCalculatorLizardSystemsFree personal · paid businessVisit lizardsystems.com Windows only. No checksum is published at the time of writing, so check the file’s digital signature details and scan it before running.

Links open the vendor’s or project’s own site in a new tab. We are none of these publishers and receive nothing when you follow a link.

A verification routine for servers

  1. Start from the address you typed. Follow a link from the table, or key in the vendor’s domain by hand, then read the address bar carefully before anything gets executed. Look-alike domains add words such as “-free” or “-pro”, or swap the top-level domain.
  2. Refuse anything that asks for less security. A page that wants you to disable antivirus, open a password-protected archive or accept “recommended offers” is not the vendor. None of the products on this site needs any of that.
  3. Check Windows signatures. From a PowerShell prompt, inspect the package:
    Get-AuthenticodeSignature .\package.exe | Format-List Status, SignerCertificate
    Expect Valid under Status, with a signer that matches the publisher listed in the table.
  4. Compare checksums where the publisher lists them. Compute the hash and compare every character with the value on the vendor’s page:
    # Windows (PowerShell)
    Get-FileHash .\package.exe -Algorithm SHA256
    # Linux / macOS
    sha256sum package.tar.gz     # or: shasum -a 256
  5. Pin open-source releases to a tag. For self-hosted web apps such as phpIPAM and NetBox, deploy a tagged release rather than whatever is on the main branch, and record the tag in your change log:
    git clone https://github.com/<project>/<repo>.git
    cd <repo> && git fetch --tags && git checkout <release-tag>
    git log -1 --format='%H %an %ad'
    For container deployments, reference the project’s official image by version tag or digest rather thanlatest.

Keep endpoint protection on

Some security products flag network scanners as potentially unwanted because probing addresses is exactly what they do. If that happens to a file you obtained from the publisher and verified as above, add a narrow exclusion for that file or folder. Never switch protection off wholesale, and never follow a website’s advice to do so. A signature or hash that fails to match means the file goes in the bin and you fetch a fresh copy from the publisher’s own site.

Next steps

Point discovery features only at address space you administer or are authorized to assess. To decide which product fits, start with the IPAM software comparison, then see the guides for step-by-step procedures.