Sign inSign up

sajadprp/nettoolbox

By sajadprp

•Updated 2 days ago

a portable network & security dashboard you carry on your laptop. One Docker container, one web UI

Image
0

148

sajadprp/nettoolbox repository overview

⁠NetToolbox

v2.2.0 — a portable network & security dashboard for network engineers, system administrators, and field technicians.

One Docker container. One web UI. Run it on your laptop, workstation, server, home lab, or client site.

Docker Docker Pulls Version License: MIT Platform No CDN

⁠Why NetToolbox?

Network and IT technicians often need several different tools during a site visit:

  • Network scanner
  • Ping and traceroute
  • Port scanner
  • SSH/Telnet client
  • RDP client
  • DNS and Whois tools
  • SSL certificate checker
  • HTTP security header checker
  • SNMP tools
  • WiFi analyzer
  • Subnet calculator
  • Wake-on-LAN
  • Hash and JWT utilities
  • Network monitoring tools

NetToolbox brings these tools together in a single browser-based dashboard running inside Docker.

No desktop installation. No separate applications. No account required.

Just pull the Docker image and start the container.


⁠Quick Start

⁠1. Pull the Docker image

Pull the latest version:

docker pull sajadprp/nettoolbox:latest

Or pull a specific version:

docker pull sajadprp/nettoolbox:v2.2.0

⁠2. Run NetToolbox

docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:latest

⁠3. Open the dashboard

Open your browser and go to:

http://127.0.0.1:8642

That's it.


⁠Run a Specific Version

If you want to run an exact version instead of latest:

docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:v2.2.0

⁠Features

⁠Network Tools

⁠Network Discovery

Discover devices on the local network using ARP and ping scanning.

Features include:

  • ARP discovery
  • Ping sweep
  • Well-known port detection
  • Host information
  • Network topology
  • CSV export
  • JSON export
⁠Port Scanner

Scan individual hosts using:

  • Custom port lists
  • Full TCP port range
  • Ports 1–65535
⁠Ping

Perform one-shot connectivity checks or monitor latency continuously.

⁠Traceroute

Trace the network path to a destination and inspect individual hops.

⁠MTR

Live MTR monitoring with:

  • Hop latency
  • Packet loss
  • Continuous monitoring
⁠Subnet Calculator

IPv4 CIDR calculator with:

  • Network address
  • Broadcast address
  • Usable host range
  • Host count
  • Typical gateway
  • Subnet splitting
⁠Neighbor Discovery

Discover network neighbors using:

  • CDP
  • LLDP

Useful for identifying connected switches, routers, and network equipment.

⁠SNMP

SNMP GET and WALK support for network devices such as:

  • Switches
  • Printers
  • UPS devices
  • Cameras
  • Network appliances
  • Dahua devices
  • Hikvision devices

Supports SNMP:

  • v1
  • v2c

Information can include:

  • Hostname
  • Uptime
  • Interface names
  • VLAN information
  • Port information
⁠WiFi Analyzer

Inspect nearby wireless networks:

  • SSID
  • Signal strength
  • Frequency
  • Nearby access points
⁠Speed Test

Check:

  • Download speed
  • Upload speed
  • Latency

The speed test uses Cloudflare's speed test infrastructure.

⁠Wake-on-LAN

Send Wake-on-LAN packets to compatible devices.

⁠ARP Table

View the local ARP table directly from the dashboard.

⁠Live Bandwidth

Monitor RX/TX traffic for network interfaces.


⁠Security Tools

⁠DNS Lookup

Query multiple DNS record types:

  • A
  • AAAA
  • MX
  • TXT
  • NS
  • CNAME
  • SOA

⁠Whois

Perform Whois lookups for domains and IP addresses.

⁠Public IP

Check the public IP address of the current network.

⁠IP Geolocation

Look up geolocation information for an IP address.

⁠Domain Recon

Passive domain reconnaissance using public certificate transparency information.

The tool can identify:

  • Main A record
  • Subdomains
  • SSL certificate-related domain information

No active scanning is performed for this feature.

⁠SSL/TLS Inspector

Inspect SSL/TLS certificates, including:

  • Public certificates
  • Internal certificates
  • Self-signed certificates

⁠HTTP Security Headers

Check HTTP security headers such as:

  • HSTS
  • CSP
  • X-Frame-Options
  • X-Content-Type-Options
  • Referrer-Policy
  • Other common security headers

⁠Hash / Base64 / JWT Toolkit

Client-side utilities for:

  • MD5
  • SHA-1
  • SHA-256
  • SHA-384
  • SHA-512
  • Base64 encode
  • Base64 decode
  • JWT decode

⁠Remote Access

⁠SSH

Use a full SSH terminal directly from the browser.

The terminal runs through ttyd and provides an interactive shell environment.

⁠Telnet

Connect to Telnet services directly from the browser.

⁠RDP

Connect to Windows desktops using:

  • FreeRDP
  • noVNC

The RDP viewer runs inside the browser.

This is useful when working with Windows machines on the same LAN as the NetToolbox host.


⁠Host Profiles

Save frequently used hosts and connection information.

Profiles can contain:

  • Hostname
  • Protocol
  • Port
  • Username
  • Site notes

Passwords are not stored in host profiles.


⁠Script Library

Keep frequently used administration commands in one place.

Supported environments include:

  • Windows
  • Linux
  • MikroTik

Scripts support variables such as:

{{HOST}}
{{USERNAME}}
{{IP}}
{{PORT}}

Scripts can be:

  • Edited
  • Copied
  • Downloaded
  • Executed over SSH

Scripts can also be used from the SSH/Telnet and RDP workflows.


⁠Site Visit Report

Generate a report containing information collected during a network site visit.

Reports can include:

  • Network discovery
  • Neighbor information
  • Link status
  • Notes

Reports can be downloaded as:

  • Markdown
  • Text

Useful for:

  • Support tickets
  • Network documentation
  • Site visit records
  • Customer reports

⁠QR Code Tools

Generate QR codes for:

  • Text
  • URLs
  • WiFi networks

QR codes can be:

  • Copied
  • Downloaded as PNG

WiFi QR codes can be generated from the current network information or entered manually.


⁠Interface

NetToolbox includes:

  • Persian UI
  • English UI
  • Light theme
  • Dark theme
  • Responsive browser interface

⁠Docker Configuration

NetToolbox requires host networking and additional network capabilities for several network-discovery features.

Recommended Docker configuration:

docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:latest
⁠Why --net=host?

Host networking allows NetToolbox to see the actual network interfaces and local network environment of the machine running the container.

This is important for features such as:

  • ARP scanning
  • Network discovery
  • CDP
  • LLDP
  • SNMP
  • Wake-on-LAN
  • Local network analysis
⁠Why NET_ADMIN?

NET_ADMIN allows the container to perform certain network administration operations required by network-analysis tools.

⁠Why NET_RAW?

NET_RAW is required by several tools that use raw network packets, including network discovery and scanning functionality.


⁠Web Interface Ports

NetToolbox uses the following local services:

ServicePortAccess
Dashboard8642Browser
Web Terminal7681Browser
RDP / noVNC7682Browser

The dashboard is intended to be accessed locally.

Use:

http://127.0.0.1:8642

⁠Security Notes

NetToolbox is a powerful network administration tool.

Because the container has access to the host network and additional network capabilities, you should understand the security implications before running it.

⁠Host networking

The container uses:

--net=host

This gives the container visibility into the host's network environment.

⁠Network capabilities

The container uses:

--cap-add=NET_ADMIN
--cap-add=NET_RAW

These capabilities are required by several network-analysis features.

⁠Terminal access

The browser terminal provides a real shell environment with tools such as:

  • SSH
  • Telnet
  • Network utilities
  • System utilities

Treat the terminal as you would any other administrative shell.

⁠RDP

RDP credentials are passed to FreeRDP through stdin rather than being placed directly on the command line.

⁠Internal certificates

NetToolbox can work with internal and self-signed certificates where certificate verification is intentionally bypassed for inspection purposes.

⁠Internet-connected features

A small number of features communicate with external services:

  • Speed Test → Cloudflare
  • Public IP / IP Geolocation → ipinfo.io
  • Domain Recon → crt.sh
  • Whois

Other functionality such as scanning, ARP discovery, CDP/LLDP, SSH/Telnet, RDP, and hashing is designed to operate locally.

Run NetToolbox only on systems and networks that you are authorized to administer.

Do not expose the dashboard publicly unless you have added your own authentication and network access controls.


⁠Updating NetToolbox

If you are using the latest tag:

docker pull sajadprp/nettoolbox:latest

Remove the old container:

docker rm -f nettoolbox

Start the updated container:

docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:latest

Your configuration and container state should be treated as disposable unless you explicitly mount persistent storage.


⁠Running on Linux

Linux provides the most predictable behavior for network-discovery features because Docker can use the host network namespace directly.

Make sure Docker is enabled at boot:

sudo systemctl enable docker
sudo systemctl start docker

Then:

docker pull sajadprp/nettoolbox:latest
docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:latest

⁠Running on Windows

NetToolbox can be run using Docker Desktop.

Install Docker Desktop, then run:

docker pull sajadprp/nettoolbox:latest

Then:

docker run -d `
  --restart unless-stopped `
  --net=host `
  --cap-add=NET_ADMIN `
  --cap-add=NET_RAW `
  --name nettoolbox `
  sajadprp/nettoolbox:latest

Network discovery behavior may vary depending on the Docker Desktop and Windows networking configuration.

Linux is recommended when direct access to the physical network interface is required.


⁠Running on macOS

NetToolbox can also be run using Docker Desktop on macOS.

Pull the image:

docker pull sajadprp/nettoolbox:latest

Run:

docker run -d \
  --restart unless-stopped \
  --net=host \
  --cap-add=NET_ADMIN \
  --cap-add=NET_RAW \
  --name nettoolbox \
  sajadprp/nettoolbox:latest

Some low-level network features may behave differently because Docker Desktop runs containers inside a Linux virtual machine.


⁠Docker Image

Docker Hub:

https://hub.docker.com/r/sajadprp/nettoolbox⁠

Available images:

sajadprp/nettoolbox:latest
sajadprp/nettoolbox:v2.2.0

Pull latest:

docker pull sajadprp/nettoolbox:latest

Pull version 2.2.0:

docker pull sajadprp/nettoolbox:v2.2.0

⁠Tech Stack

  • Python
  • Flask
  • Nmap
  • arp-scan
  • tshark
  • dig
  • OpenSSL
  • iw
  • traceroute
  • curl
  • ttyd
  • FreeRDP
  • noVNC
  • JavaScript
  • HTML
  • CSS

The application is designed to be self-contained and does not require external CDN dependencies for the main web interface.


⁠License

MIT License.

See LICENSE for the complete license text.

Tag summary

Content type

Image

Digest

sha256:9e9c42722…

Size

286.5 MB

Last updated

2 days ago

docker pull sajadprp/nettoolbox:v2.3.0