Operating System Notes
Learn how AssetLoom Network Scanner behaves across supported operating systems, including platform-specific permissions, commands, and network discovery limitations.
AssetLoom Network Scanner supports macOS, Windows, and Linux, but the way you run the scanner and grant the required system permissions differs by operating system.
You can use this guide when you need platform-specific instructions for running the scanner or troubleshooting permission-related discovery issues.
1. For macOS & Linux
Run the Scanner with Administrator Access
For the best discovery coverage on macOS/Linux, run the scanner with sudo.
For example sudo ./assetloom-scanner --config ./config.json --output ./devices.csv TARGET
Without elevated permissions, the scanner may still run, but ICMP or ARP discovery can be limited. You can run a dry run to check whether these protocols are available before scanning.
Make the Scanner Executable
If macOS returns a permission error when you try to run the downloaded scanner, make the binary executable: chmod +x ./assetloom-scanner
You normally need to do this only once for the downloaded binary.
If macOS Blocks the Scanner
macOS may prevent an unsigned downloaded binary from running.
Only run a Network Scanner binary that you downloaded from an official or organization-approved AssetLoom distribution channel.
If the scanner is blocked, review the macOS security message before proceeding and make sure the file is the AssetLoom release you intended to use.
Optional: Use Linux File Capabilities
If your organization permits Linux file capabilities, you may be able to grant the scanner raw-socket capability instead of running the entire scanner with sudo: sudo setcap cap_net_raw+ep ./assetloom-scanner
Keep in mind that file capabilities may be lost if you copy or replace the scanner binary.
2. For Windows
Run from an Administrator Terminal
For the best discovery coverage on Windows, open PowerShell or Command Prompt as Administrator before running the scanner.
For example: .\assetloom-scanner.exe --config .\config.json --output .\devices.csv TARGET
Running without Administrator access may limit some discovery methods. Use a dry run to check protocol capability if you are unsure.
Keep the .exe Extension
Unlike macOS and Linux, the Windows scanner should keep its .exe extension.
If you kept the original downloaded filename, your command may look like: .\assetloom-scanner.exe --version
You can replace the filename in the examples with the actual scanner filename on your computer.
Quick Comparison
| macOS | Windows | Linux | |
|---|---|---|---|
| Recommended elevated access | sudo | Administrator terminal | sudo |
| Executable permission may be required | Yes | No | Yes |
| Typical scanner command | ./assetloom-scanner | .\assetloom-scanner.exe | ./assetloom-scanner |
| Path style | ./config.json | .\config.json | ./config.json |
| Alternative raw-socket capability | — | — | setcap where permitted |
If discovery behaves differently than expected on your operating system, run a dry run and review Protocol Capability first. This will show whether ICMP, ARP, and the other configured discovery methods are available on the scanner host.