Safe sourcing
Where to get each tool
Scan 365 Pro hosts no programs and mirrors nothing. This page lists where each tool legitimately comes from and how to check it before it goes anywhere near a production machine.
Last reviewed · Husanjon Ruzaliev, editor
Why there are no copies here
Admin tools are a favourite costume for malware. Lookalike domains borrow names like Wireshark or PingPlotter, wrap the real program in extras, and rely on a busy admin not reading the address bar during an outage. A tool that will run with elevated rights on a server deserves a cleaner supply chain than that, and a third-party copy can only ever be as trustworthy as the original — usually less. So we keep it simple: every link on Scan 365 Pro opens the maker’s own page, and the rest of this page explains how to check what you get there.
The vendor’s own site for all 9 tools
| Tool | Made by | Licence | Vendor page | Cleanest route and what to check |
|---|---|---|---|---|
| PingPlotter | Pingman Tools | Commercial | Visit pingplotter.com | Windows and macOS editions from pingplotter.com. On Windows, the digital signature should name the vendor, Pingman Tools. |
| mtr | BitWizard / open-source maintainers | Open source | Visit bitwizard.nl | Your OS package manager: apt install mtr, dnf install mtr, or brew install mtr on macOS. Source code is linked from the project page. |
| SmokePing | Tobias Oetiker | Open source | Visit oss.oetiker.ch | Your Linux distribution’s package where one exists; otherwise the release archives linked from the project site. Perl modules, RRDtool and fping come from the OS repositories. |
| Obkio Network Performance Monitoring | Obkio | SaaS | Visit obkio.com | A hosted service: sign up on obkio.com. Monitoring agents are deployed from inside your own Obkio account, not from third-party sites. |
| iPerf3 | ESnet | Open source | Visit software.es.net | ESnet publishes source code only: use apt install iperf3, dnf install iperf3 or brew install iperf3. ESnet ships no Windows builds, so any Windows binary comes from a third party — weigh that before running it. |
| Wireshark | Wireshark Foundation | Open source | Visit wireshark.org | wireshark.org, which publishes a signed list of SHA-256 hashes for every release; Windows and macOS builds are code-signed. On Linux, the distribution package is the simplest trustworthy route. |
| TCPView | Microsoft Sysinternals | Freeware | Visit learn.microsoft.com | Microsoft’s Sysinternals pages on learn.microsoft.com, also bundled in the Sysinternals Suite. The files are signed by Microsoft Corporation. |
| Angry IP Scanner | Anton Keks | Open source | Visit angryip.org | angryip.org, which points to the project’s published releases. Linux users can use the .deb or .rpm packages listed there. |
| LizardSystems Network Scanner | LizardSystems | Paid for business | Visit lizardsystems.com | lizardsystems.com only. The product page publishes a SHA-256 value for the current Windows build; check it with Get-FileHash before the first run. |
Links open in a new tab. Scan 365 Pro is none of these vendors and receives nothing when you follow a link.
Prefer a package manager where one exists
Five of the nine tools here are open source and packaged by every mainstream Linux distribution and by Homebrew on macOS. A package manager checks signatures for you, pulls dependencies from the same trusted repositories and makes updates routine, which is why it is the first choice for mtr, SmokePing, iPerf3 and, on Linux, Wireshark:
# Debian / Ubuntu
sudo apt install mtr-tiny iperf3 wireshark smokeping
# Fedora / RHEL family (EPEL may be needed for some)
sudo dnf install mtr iperf3 wireshark
# macOS with Homebrew
brew install mtr iperf3Package names vary slightly between distributions; apt search or dnf search will confirm them.
Check the signature on Windows
For a Windows program, open the file’s Properties and look at the Digital Signatures tab: the signer should be the vendor in the table above. From PowerShell, the same check is scriptable, which helps when you are staging tools for several technicians:
Get-AuthenticodeSignature .\received-file |
Select-Object Status, @{n='Signer';e={$_.SignerCertificate.Subject}}Status must read Valid. NotSigned or HashMismatch means stop and start again from the vendor’s page.
Check the signature on macOS
codesign --verify --deep --strict --verbose=2 /Applications/Example.app
spctl --assess --type execute --verbose /Applications/Example.appThe second command should say accepted and name the developer you expect.
Compare a published hash
Wireshark and LizardSystems publish SHA-256 values for their builds. Compute the hash of the file you received and compare every character, not just the first few:
Get-FileHash .\received-file -Algorithm SHA256 # Windows
shasum -a 256 received-file # macOS
sha256sum received-file # LinuxWhen endpoint protection objects
Security products sometimes flag range scanners and packet-capture drivers as “potentially unwanted”, simply because sweeping and capturing are what attackers do too. If a file from the vendor passes the checks above, request a narrow exclusion covering just that file or folder, via the change process you already use. Turning protection off across the board is never the answer, and a page that advises it is itself a warning sign.
Then point it at the right network
Run these tools only against networks and hosts you administer, or where the owner has given written permission. Not sure which one you need? Start with the latency and path comparison, or pick a guide that matches your ticket.