Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

tcpcat is an open-source network reconnaissance tool written in Go. It covers network discovery, port and service enumeration, vulnerability-data correlation, and detection logic written as sandboxed WebAssembly modules. Its faster packet path, eBPF/AF_XDP, is optional and works only where your Linux kernel, network driver, and privileges support it. The speed figures on the project page are the maintainer’s own measurements, not independent tests. The project describes itself as a personal community project intended for learning, network administration, and authorized security testing.

What tcpcat does

According to the official tcpcat repository, the tool documents the following capabilities. These are features the project describes; they have not been independently verified.

  • Transport enumeration: TCP, UDP, and ICMP enumeration.
  • Service fingerprinting: service topology and version fingerprinting.
  • Discovery: asynchronous DNS, mDNS, and NetBIOS discovery.
  • Vulnerability correlation: matching against Vulners, Google OSV, or an offline database. A version or banner match is a lead to validate, not proof that a system is exploitable.
  • Detection extensions: WASM detection modules that run in a sandbox, and custom protocol dissectors that can be written in Rust, C, Go, or AssemblyScript.

The practical question most readers bring is whether tcpcat can answer two things at once: what is on a network, and whether their monitoring stack sees the traffic used to find it. The repository lists that second scenario explicitly, with packet-level controls intended to check how an authorized team’s IDS or IPS records varied traffic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where the eBPF/AF_XDP path fits

The title’s eBPF/AF_XDP element is an optional packet-I/O path, not the default way the tool works. AF_XDP is a Linux mechanism that pairs XDP programs with sockets and userspace packet buffers. The Linux kernel documentation for AF_XDP describes RX and TX rings and a shared memory region called UMEM that holds packet buffers.

#1 Best Overall
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

How fast that path runs depends on which XDP mode the kernel and driver provide. The kernel documentation distinguishes two modes that matter here.

Generic mode: XDP_SKB

XDP_SKB is the generic fallback. It works without special driver support, which makes it the easiest mode to get running, but it does not give you the full benefit of the fast path.

Driver mode: XDP_DRV

XDP_DRV is driver-backed. It is available only when the network driver implements XDP support, and its behavior varies by hardware. Do not assume that AF_XDP means zero-copy operation or identical throughput across machines. The kernel documentation describes several modes with hardware-dependent results, so the mode you actually get is the one that matters.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Wintertion1U/Desktop/Rackmount Firewall Hardware,OPNsense, VPN, Network Security Appliance, Router PCN2600 D2700, 4 x Gigabit LAN, COM, VGA, Fan, 0 RAM, 0 Storage (Desktop Type, 4G RAM 64G SSD)
  • equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
  • There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product

Requirements before you install

The repository lists the following requirements. Check the current README before installing, because version numbers change between releases.

Requirement Documented value Why it matters
Linux kernel 5.8 or later, for optional eBPF/XDP operation Without it, the AF_XDP path is unavailable; the tool’s standard operation is not affected by this line alone.
Go toolchain 1.26 or later Needed to build the project from source.
Raw-socket privileges CAP_SYS_ADMIN or root Raw socket operations are not available to an unprivileged user.
eBPF compiler gcc or clang, optional Needed only if you compile eBPF programs yourself.
Other platforms macOS and others are described as having more limited capabilities Check the platform table in the repository before planning a deployment outside Linux.

Kernel version alone does not confirm the fast path. You also need a driver that supports the XDP mode you want, which you can only confirm on the target machine.

Performance claims and how to read them

The repository publishes benchmark figures. Each one should be read with the conditions the project attached to it, as summarized below.

Rank #3
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
Claim Figure Conditions stated
Packet throughput Approximately 1 million packets per second per core Associated by the project with its eBPF/AF_XDP mode. The hardware and test setup are not described in the excerpt reviewed.
Ports 1–1024, tcpcat versus Nmap tcpcat 80 ms; Nmap 1.9–2.3 seconds Repository-reported baseline values. The excerpt does not state which tcpcat mode was used or the test environment.
Full 1–65,535 SYN scan across two hosts tcpcat eBPF/XDP 4.466 seconds; Nmap 11.723 seconds; naabu 20.945 seconds A 25,000 packets-per-second rate limit and three runs, as described in the repository. Published by the project, not an independent benchmark.

The figures show what the project measured in its own setup. They do not show what your network, driver, or kernel will deliver. The comparisons are also project-authored, so if you are choosing between scanners, rerun the same scan profile on your own hardware before drawing conclusions. A companion overview posted on DEV Community on 2026-10-01 summarizes the project in similar terms; where the two differ, the repository takes precedence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Using tcpcat within authorization

The project frames tcpcat as a dual-use assessment tool. Its documentation sets the following conditions for scanning systems you do not own or administer:

  • Explicit written authorization from the system owner.
  • A documented scope that names the targets.
  • A defined assessment window.

The repository is direct about the limits of its evasion-style options. Fragmentation, decoy traffic, and timing variation are described as tools for checking monitoring visibility. The project states: “These controls do not guarantee detection avoidance or IDS/IPS bypass.” Treat them as a way to test what your sensors record, not as a way to avoid being seen.

Rank #4
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Project status and support

tcpcat is described as a personal open-source community project, not a commercial product. The repository states that it offers no hosted scanning service, no paid support, no managed assessments, and no customer accounts. Questions about behavior or bugs should go through the project’s public repository, and there is no vendor support contract behind the tool.

Evaluating tcpcat against other scanners

If you are comparing tcpcat with another scanner, compare the things that affect your job rather than headline speed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Protocol coverage: TCP, UDP, and ICMP, plus discovery protocols.
  • Fingerprinting depth and vulnerability-data sources.
  • Extensibility through detection modules and dissectors.
  • Operating-system support, kernel and driver requirements, and privileges needed.
  • Rate controls and scope safeguards.
  • Performance measured on your own hardware under your own scan profile.

The project’s documentation covers tcpcat only. It does not evaluate competing tools, so any comparison you make will need your own testing.

tcpcat is worth evaluating if you run Linux, can meet its kernel and privilege requirements, and want one tool that combines discovery, fingerprinting, and programmable detections under a clear authorization model. Verify the kernel, driver, and privilege requirements on your target machine before committing to the AF_XDP path.

Sources: tcpcat repository and README; Linux kernel documentation, AF_XDP; tcpcat project post on DEV Community, published 2026-10-01.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.